Back

MEDIUM

Fedora CoreOS supports setting a GRUB bootloader password

Published Nov 3, 2022

Description

Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent Fedora CoreOS releases have a misconfiguration which allows booting non-default OSTree deployments without entering a password. This allows someone with access to the GRUB menu to boot into an older version of Fedora CoreOS, reverting any security fixes that have recently been applied to the machine. A password is still required to modify kernel command-line arguments and to access the GRUB command line.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fedora
Published Nov 3, 2022
Updated May 2, 2025
Reserved Oct 24, 2022
CISA Vulnrichment
Updated May 2, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner fedora
Published Nov 3, 2022
Updated May 2, 2025
Exploited since n/a
EUVD-2022-43034