A flaw in grub2 was found where its configuration file known as grub.cfg is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.
🔗 CVE IDs covered (1)
📋 Description
Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
🎯 Affected products4
- azl3 grub2 2.06-14 on Azure Linux 3.0
- azl3 grub2 2.06-23 on Azure Linux 3.0
- cbl2 grub2 2.06-5 on CBL Mariner 2.0
- cm1 grub2 2.06~rc1-8 on CBL Mariner 1.0
✅ Remediation
KBCBL-Mariner Releases (Security Update) — fixed build - KBCBL-Mariner Releases (Security Update) — fixed build 2.06-5 KBCBL-Mariner Releases (Security Update) — fixed build 2.06-14