RedHat: RHSA-2022-2110:01 Low: grub2 security, bug fix,
Summary
The grub2 packages provide version 2 of the Grand Unified Boot Loader
(GRUB), a highly configurable and customizable boot loader with modular
architecture. The packages support a variety of kernel formats, file
systems, computer architectures, and hardware devices.
Security Fix(es):
* grub2: Incorrect permission in grub.cfg allow unprivileged user to read
the file content (CVE-2021-3981)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.6 Release Notes linked from the References section.
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2021-3981 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.6_release_notes/
Package List
Red Hat Enterprise Linux BaseOS (v. 8):
Source:
grub2-2.02-123.el8.src.rpm
aarch64:
grub2-debuginfo-2.02-123.el8.aarch64.rpm
grub2-debugsource-2.02-123.el8.aarch64.rpm
grub2-efi-aa64-2.02-123.el8.aarch64.rpm
grub2-efi-aa64-cdboot-2.02-123.el8.aarch64.rpm
grub2-tools-2.02-123.el8.aarch64.rpm
grub2-tools-debuginfo-2.02-123.el8.aarch64.rpm
grub2-tools-extra-2.02-123.el8.aarch64.rpm
grub2-tools-extra-debuginfo-2.02-123.el8.aarch64.rpm
grub2-tools-minimal-2.02-123.el8.aarch64.rpm
grub2-tools-minimal-debuginfo-2.02-123.el8.aarch64.rpm
noarch:
grub2-common-2.02-123.el8.noarch.rpm
grub2-efi-aa64-modules-2.02-123.el8.noarch.rpm
grub2-efi-ia32-modules-2.02-123.el8.noarch.rpm
grub2-efi-x64-modules-2.02-123.el8.noarch.rpm
grub2-pc-modules-2.02-123.el8.noarch.rpm
grub2-ppc64le-modules-2.02-123.el8.noarch.rpm
ppc64le:
grub2-debuginfo-2.02-123.el8.ppc64le.rpm
grub2-debugsource-2.02-123.el8.ppc64le.rpm
grub2-ppc64le-2.02-123.el8.ppc64le.rpm
grub2-tools-2.02-123.el8.ppc64le.rpm
grub2-tools-debuginfo-2.02-123.el8.ppc64le.rpm
grub2-tools-extra-2.02-123.el8.ppc64le.rpm
grub2-tools-extra-debuginfo-2.02-123.el8.ppc64le.rpm
grub2-tools-minimal-2.02-123.el8.ppc64le.rpm
grub2-tools-minimal-debuginfo-2.02-123.el8.ppc64le.rpm
x86_64:
grub2-debuginfo-2.02-123.el8.x86_64.rpm
grub2-debugsource-2.02-123.el8.x86_64.rpm
grub2-efi-ia32-2.02-123.el8.x86_64.rpm
grub2-efi-ia32-cdboot-2.02-123.el8.x86_64.rpm
grub2-efi-x64-2.02-123.el8.x86_64.rpm
grub2-efi-x64-cdboot-2.02-123.el8.x86_64.rpm
grub2-pc-2.02-123.el8.x86_64.rpm
grub2-tools-2.02-123.el8.x86_64.rpm
grub2-tools-debuginfo-2.02-123.el8.x86_64.rpm
grub2-tools-efi-2.02-123.el8.x86_64.rpm
grub2-tools-efi-debuginfo-2.02-123.el8.x86_64.rpm
grub2-tools-extra-2.02-123.el8.x86_64.rpm
grub2-tools-extra-debuginfo-2.02-123.el8.x86_64.rpm
grub2-tools-minimal-2.02-123.el8.x86_64.rpm
grub2-tools-minimal-debuginfo-2.02-123.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Topic
An update for grub2 is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Low. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, noarch, ppc64le, x86_64
Bugs Fixed
1809246 - [RFE] GRUB does not consider information from proxy dhcp server
1899903 - grub2-mkconfig is never run on kernel upgrade even if GRUB_ENABLE_BLSCFG=false
1914575 - grub-boot-success.service should not be started inside systemd-nspawn container
2016269 - RPM grub2-tools-minimal is shipping prelink config files although prelink is absent in rhel8
2020927 - GRUB_TERMINAL_INPUT=at_keyboard makes grub stay on boot menu instead of starting the timeout
2024170 - CVE-2021-3981 grub2: Incorrect permission in grub.cfg allow unprivileged user to read the file content
2048904 - Cannot EFI chainload onto local disk when EFI partition is in Software Raid
2061252 - grub on OpenFirmware : search --hint-ieee1275= does not work
2069157 - grub2 signed by Red Hat Test Certificate