In the Linux kernel, the following vulnerability has been resolved: efivarfs: force RO when remounting if SetVariable is not supported If SetVariable at runtime is not supported by the firmware we never assign a callback for that function. At the same time mount the efivarfs as RO so no one can call that. However, we never check the permission flags when someone remounts the filesystem as RW. As a result this leads to a crash
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Kernel-5.10 Extra | kernel | 2024-02-01 20:10 | ALAS2KERNEL-5.10-2024-048 |
Amazon Linux 2 - Kernel-5.15 Extra | kernel | 2024-02-01 20:10 | ALAS2KERNEL-5.15-2024-036 |
Amazon Linux 2023 | kernel | 2024-02-15 02:51 | ALAS2023-2024-519 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 4.4 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |