A vulnerability in Red Hat patches for the GRUB2 bootloader that allows bypassing password verification.

Information has been revealed about the vulnerability (CVE-2023-4001) in patches for the GRUB2 bootloader prepared by Red Hat. This vulnerability allows bypassing the password check set in GRUB2 to limit access to the boot menu or command line on many systems with UEFI. The issue stems from a modification added by Red Hat to the GRUB2 package provided in RHEL and Fedora Linux. The problem does not affect the main GRUB2 project and only impacts distributions that have applied additional Red Hat patches.

The issue is caused by a flaw in the logic of using UUID to locate the device containing the configuration file (e.g., "/boot/efi/EFI/fedora/grub.cfg") that contains the password hash. To bypass authentication, a user with physical access to the computer can connect an external drive, such as a USB flash drive, and set its UUID to mirror the identifier of the boot partition of the attacked system.

Many UEFI systems prioritize external drives, listing them ahead of internal drives during device detection. Therefore, the partition prepared by the attacker on the external drive will take precedence during processing, and GRUB2 will attempt to load the configuration file from that partition. During the search for the partition using the "search" command in GRUB2, only the first matching UUID is determined, after which the search stops. If the main configuration file is not found in the specified partition, GRUB2 will present a command line prompt, allowing complete control over the subsequent boot process.

A local unprivileged user can use the "lsblk" utility to determine the UUID of the partition, but an outsider without access to the system, yet capable of observing the boot process, can sometimes identify the UUID from the diagnostic messages shown during boot in certain distributions. The vulnerability has been addressed by Red Hat by adding a new argument to the "search" command, which restricts the UUID scanning operation to only those block devices used to launch the boot manager (i.e., the boot partition must be on the same disk as the system EFI partition).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster