Relax-and-Recover (aka ReaR) through 2.7 creates a world...
Moderate severity
Unreviewed
Published
Jan 13, 2024
to the GitHub Advisory Database
•
Updated Jun 4, 2025
Description
Published by the National Vulnerability Database
Jan 12, 2024
Published to the GitHub Advisory Database
Jan 13, 2024
Last updated
Jun 4, 2025
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
References