Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:3184 - Security Advisory
Issued:
2024-05-22
Updated:
2024-05-22

RHSA-2024:3184 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: grub2 security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for grub2 is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.

Security Fix(es):

  • grub2: grub2-set-bootflag can be abused by local (pseudo-)users (CVE-2024-1048)
  • grub2: Out-of-bounds write at fs/ntfs.c may lead to unsigned code execution (CVE-2023-4692)
  • grub2: out-of-bounds read at fs/ntfs.c (CVE-2023-4693)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.10 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2236613 - CVE-2023-4692 grub2: Out-of-bounds write at fs/ntfs.c may lead to unsigned code execution
  • BZ - 2238343 - CVE-2023-4693 grub2: out-of-bounds read at fs/ntfs.c
  • BZ - 2256827 - CVE-2024-1048 grub2: grub2-set-bootflag can be abused by local (pseudo-)users
  • RHEL-4314 - "Weak" grub2.cfg file generated on PPC64LE platform
  • RHEL-4343 - Updating a kernel makes it become the default even if its "family" is not the expected one

CVEs

  • CVE-2023-4692
  • CVE-2023-4693
  • CVE-2024-1048

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.10_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
grub2-2.02-156.el8.src.rpm SHA-256: 3db8b43cf3de02cfb5fd1367f2f19d27b266b35ba8066711586892d94c3eb46a
x86_64
grub2-common-2.02-156.el8.noarch.rpm SHA-256: a4093604239949b2d106632bfc93302f8ff63f9a639c4acaf6e5fae942159384
grub2-debuginfo-2.02-156.el8.x86_64.rpm SHA-256: 785868a81bbfc4f7e1c45ffb1bf7754af6dbb9b07dcb3cd21021331f399d599c
grub2-debugsource-2.02-156.el8.x86_64.rpm SHA-256: a707bd5b9465ecfa758e98f93da4f422a94db87f93f4ca90231c9f972a7cd6e4
grub2-efi-aa64-modules-2.02-156.el8.noarch.rpm SHA-256: 9d7f2d9ea6117d4b9025d58c28d2eb678206057602d26f5ce807b50fae4a2829
grub2-efi-ia32-2.02-156.el8.x86_64.rpm SHA-256: 799ed5daa4bf2a5bfee5431d32ff2f66c421df1796fcbf60d227524d10a24c30
grub2-efi-ia32-cdboot-2.02-156.el8.x86_64.rpm SHA-256: 1cd92018909b5564050e0908bd180a2bed3b32eea5c8719803bf658e91b16fb2
grub2-efi-ia32-modules-2.02-156.el8.noarch.rpm SHA-256: 177125886f0478ee743a805f9231b5d5d4714ca76202aec7f3cdcac5937e0ffe
grub2-efi-x64-2.02-156.el8.x86_64.rpm SHA-256: ea86a3f183a781567c8567fab0b576fd856b1ad4cd83f7970f2ff1a4ed1c8c01
grub2-efi-x64-cdboot-2.02-156.el8.x86_64.rpm SHA-256: 71fb60f7b51257243fd4c4ba03ad26c0e2a95e6e7f2c2a82cd04b5489cc1e74f
grub2-efi-x64-modules-2.02-156.el8.noarch.rpm SHA-256: c997fe02ce32c49d3a37115cff2a8adcbf8b3f97767bb544e83f69950bc58152
grub2-pc-2.02-156.el8.x86_64.rpm SHA-256: a6f049b39ae564ee13d79076780874e79a8526cc805c37064142a98e7e2a1ab2
grub2-pc-modules-2.02-156.el8.noarch.rpm SHA-256: b386de2cc6a77f35ba3633ae43c766a94d13cbe18f675e56983599b4cac29c33
grub2-ppc64le-modules-2.02-156.el8.noarch.rpm SHA-256: 23f71d6ad28feb69a0452a07a1c4e8c707dce0b0e04c85d5e064bcd5c7fa1997
grub2-tools-2.02-156.el8.x86_64.rpm SHA-256: e54252da281c398cd570ace3ed1641c86853c0e5c312349d77ed50c8939f730f
grub2-tools-debuginfo-2.02-156.el8.x86_64.rpm SHA-256: 44eae89e5b5f7db7b15b22e881e999d741d71c5702302e7cdccae480331771c6
grub2-tools-efi-2.02-156.el8.x86_64.rpm SHA-256: a9298cea11176848592a4a4c16d009313c3629eec12bbf0f71f653522aa0428c
grub2-tools-efi-debuginfo-2.02-156.el8.x86_64.rpm SHA-256: ff77f1512698b394033f9b2e542a7afdaf24c074a6d49530289d5722ddcee8d5
grub2-tools-extra-2.02-156.el8.x86_64.rpm SHA-256: bbe913ede5814b3698fbd0379f3f27e34f3cd9e5761056b5d645fedc69adbf6a
grub2-tools-extra-debuginfo-2.02-156.el8.x86_64.rpm SHA-256: ed4c291e3a4e456d26527d9898f26da24fb464ad9bf158d081058e728bdfdce5
grub2-tools-minimal-2.02-156.el8.x86_64.rpm SHA-256: 3645cc1acc709cc0c221c8f15a327e00a2e3646cd787b7c90563c9cfa6415f6e
grub2-tools-minimal-debuginfo-2.02-156.el8.x86_64.rpm SHA-256: 72796c3d7deda34706cd62ddd3b7f3dc179c5f83914146bff4a87c81265dd469

Red Hat Enterprise Linux for Power, little endian 8

SRPM
grub2-2.02-156.el8.src.rpm SHA-256: 3db8b43cf3de02cfb5fd1367f2f19d27b266b35ba8066711586892d94c3eb46a
ppc64le
grub2-common-2.02-156.el8.noarch.rpm SHA-256: a4093604239949b2d106632bfc93302f8ff63f9a639c4acaf6e5fae942159384
grub2-debuginfo-2.02-156.el8.ppc64le.rpm SHA-256: 9b68f03bd64bdaf78e51a344128536ab287ae0e16a01776fa0bb2871b5f906b0
grub2-debugsource-2.02-156.el8.ppc64le.rpm SHA-256: 68df39495bbbc3a3c2edf5b2665d623259c0a5089041d8f0f2b940fe37294052
grub2-efi-aa64-modules-2.02-156.el8.noarch.rpm SHA-256: 9d7f2d9ea6117d4b9025d58c28d2eb678206057602d26f5ce807b50fae4a2829
grub2-efi-ia32-modules-2.02-156.el8.noarch.rpm SHA-256: 177125886f0478ee743a805f9231b5d5d4714ca76202aec7f3cdcac5937e0ffe
grub2-efi-x64-modules-2.02-156.el8.noarch.rpm SHA-256: c997fe02ce32c49d3a37115cff2a8adcbf8b3f97767bb544e83f69950bc58152
grub2-pc-modules-2.02-156.el8.noarch.rpm SHA-256: b386de2cc6a77f35ba3633ae43c766a94d13cbe18f675e56983599b4cac29c33
grub2-ppc64le-2.02-156.el8.ppc64le.rpm SHA-256: 950322fa7ee4fa4ebe98c69f330f15616b230bfe281ca16377e32800a0b981db
grub2-ppc64le-modules-2.02-156.el8.noarch.rpm SHA-256: 23f71d6ad28feb69a0452a07a1c4e8c707dce0b0e04c85d5e064bcd5c7fa1997
grub2-tools-2.02-156.el8.ppc64le.rpm SHA-256: 76e89d7f1d9a539c96e83252dd3074d6160ccd58f95d9e5f4c8ae9541b75ba83
grub2-tools-debuginfo-2.02-156.el8.ppc64le.rpm SHA-256: 905dc41245521c5d64e482ea409d5e2cd60717cb0ba37521a3c0a86c677b63e8
grub2-tools-extra-2.02-156.el8.ppc64le.rpm SHA-256: 390e5271255523cd38a631272289a2e6ea30ae290f7fff94833f39ba8a0af129
grub2-tools-extra-debuginfo-2.02-156.el8.ppc64le.rpm SHA-256: 55241655e53b1558898120b2ccc445f26d331c80d2651143b6c660c03a209f78
grub2-tools-minimal-2.02-156.el8.ppc64le.rpm SHA-256: 46dbcef4d7f9ac0d05d6b098a2bd58ed0d903018852b99cd2a9830e71687df34
grub2-tools-minimal-debuginfo-2.02-156.el8.ppc64le.rpm SHA-256: 43218ac17f64ea238e71359f29e0db11682ae0ed4d29d1d3c157eaad13675fe0

Red Hat Enterprise Linux for ARM 64 8

SRPM
grub2-2.02-156.el8.src.rpm SHA-256: 3db8b43cf3de02cfb5fd1367f2f19d27b266b35ba8066711586892d94c3eb46a
aarch64
grub2-common-2.02-156.el8.noarch.rpm SHA-256: a4093604239949b2d106632bfc93302f8ff63f9a639c4acaf6e5fae942159384
grub2-debuginfo-2.02-156.el8.aarch64.rpm SHA-256: a2433cc0317a7d8d00fa676e40bf05c550b8faa667d025277eb4111ae387c1f0
grub2-debugsource-2.02-156.el8.aarch64.rpm SHA-256: 66f8e56307b4b13d032e8f642f9605eeb53d07308fe05da635b984beaaad0dea
grub2-efi-aa64-2.02-156.el8.aarch64.rpm SHA-256: 6cfb4cbe459c6ead3a4e2899ae89b1e37ee2b616528624368e4af143cf310ba2
grub2-efi-aa64-cdboot-2.02-156.el8.aarch64.rpm SHA-256: 03b10000702760959b1b7f4a450fca893ec4ba3fc5d540486a3827fe0cce89c1
grub2-efi-aa64-modules-2.02-156.el8.noarch.rpm SHA-256: 9d7f2d9ea6117d4b9025d58c28d2eb678206057602d26f5ce807b50fae4a2829
grub2-efi-ia32-modules-2.02-156.el8.noarch.rpm SHA-256: 177125886f0478ee743a805f9231b5d5d4714ca76202aec7f3cdcac5937e0ffe
grub2-efi-x64-modules-2.02-156.el8.noarch.rpm SHA-256: c997fe02ce32c49d3a37115cff2a8adcbf8b3f97767bb544e83f69950bc58152
grub2-pc-modules-2.02-156.el8.noarch.rpm SHA-256: b386de2cc6a77f35ba3633ae43c766a94d13cbe18f675e56983599b4cac29c33
grub2-ppc64le-modules-2.02-156.el8.noarch.rpm SHA-256: 23f71d6ad28feb69a0452a07a1c4e8c707dce0b0e04c85d5e064bcd5c7fa1997
grub2-tools-2.02-156.el8.aarch64.rpm SHA-256: a2d3f78ca8cc704ff80541dd06b5188f9fc51785e3b2e833f47878f534908d70
grub2-tools-debuginfo-2.02-156.el8.aarch64.rpm SHA-256: 0835d678d6d8079d62933515c770bc354db471c60a09cf33489b7e4486610223
grub2-tools-extra-2.02-156.el8.aarch64.rpm SHA-256: 2b874c66ff20a2f0b026a56b7a4e123045e3b745eeaabe39cc154f41d53a5da8
grub2-tools-extra-debuginfo-2.02-156.el8.aarch64.rpm SHA-256: 22d81940cbdbc17f2fe91ab3c3a83526453687cfb4e42bb1eacbde4fbe4f7b42
grub2-tools-minimal-2.02-156.el8.aarch64.rpm SHA-256: 94518e5afe908f188940fc43e26d1e86e1aac8c8bb50d5f7b81e41cc1a6ac7e7
grub2-tools-minimal-debuginfo-2.02-156.el8.aarch64.rpm SHA-256: ccf773b0cf3ae00e30ec67fa57ddb054dfea3aaee94b7f1686ccbe88ae4a8fb4

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility