CVE-2021-3981

LOW

GRUB2 < 2.06 - Unprotected Configuration File Permissions

Title source: llm
STIX 2.1

Description

A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.

References (4)

Core 4
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2024170
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202209-12

Scores

CVSS v3 3.3
EPSS 0.0002
EPSS Percentile 7.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-276
Status published
Products (2)
fedoraproject/fedora 34
gnu/grub2 < 2.06
Published Mar 10, 2022
Tracked Since Feb 18, 2026