CVE-2021-46705
MEDIUMgrub2 <2.06-150400.7.1, <2.06-18.1 - Local File Truncation
Title source: llmDescription
A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to 2.06-18.1.
Scores
CVSS v3
5.1
EPSS
0.0004
EPSS Percentile
13.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Details
CWE
CWE-377
Status
published
Products (1)
gnu/grub2
< 2.06-150400.7.1
Published
Mar 16, 2022
Tracked Since
Feb 18, 2026