Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23301


Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.


Published

2024-01-12T23:15:10.030

Last Modified

2025-06-04T16:15:30.847

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application relax-and-recover relax-and-recover ≤ 2.7 Yes
Operating System suse linux_enterprise 15.0 Yes
Operating System redhat enterprise_linux 8.0 Yes
Operating System redhat enterprise_linux 9.0 Yes
Operating System fedoraproject fedora 39 Yes

References