grub2: grub2-set-bootflag utility causes grubenv corruption rendering the system non-bootable
Published Nov 29, 2019
5.9
MEDIUMCVSS 3.1
EPSS 0.32%
Description
A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.
Affected products
- Vendor n/a Product Grub2 Defaultn/a
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| n/a | Grub2 | n/a |
|
Running on/with
- 8.0
- 8.1
- 8.2
- 8.4
- 8.6
- 8.8
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
- 8.8
No data.
Red Hat Enterprise Linux 8
grub2-1:2.02-78.el8_1.1
Fixed · RHSA-2020:0335
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | grub2-1:2.02-78.el8_1.1 | Fixed | RHSA-2020:0335 |
No package ranges for this CVE.
Remediation
Red Hat statement
grub-set-bootflag is a command line to set bootflags in GRUB's stored environment. This is a downstream utility which is shipped with Red Hat Enterprise Linux 8 and Fedora. A flaw was found in this application which would could allow a local attacker (someone having a local account on the system) to cause grub configuration files to be truncated. Whenever the machine was rebooted, grub would fail to read the configuration files and the system would be rendered unbootable.
Red Hat mitigation
Remove the "grub-set-bootflag" from the system, by manually the deleting the binary file. Note: On subsequent updates of the "grub2-tools-minimal" rpm, the file will be re-installed.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
AV:L/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.32% (0.00324) | 23.08th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.32% (0.00324) | 25.66th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00042) | 5.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00890) | 30.33th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00890) | 26.62th | v2 (v2022.01.01) |
| Jan 6, 2022 | 1.96% (0.01960) | 49.57th | v1 |
| Jan 5, 2022 | 0.44% (0.00444) | 29.04th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.44% (0.00444) | 0.00th | v1 |
References (8)
- http://www.openwall.com/lists/oss-security/2024/02/06/3 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0335 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-14865 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1764925 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14865 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14865
- https://seclists.org/oss-sec/2019/q4/101 x_refsource_MISCMailing ListThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14865
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2024/02/06/3 | Third Party Advisory | |
| https://access.redhat.com/errata/RHSA-2020:0335 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-14865 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1764925 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14865 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-14865 | ||
| https://seclists.org/oss-sec/2019/q4/101 | x_refsource_MISCMailing ListThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-14865 |
Change history (0)
No recorded changes yet.