A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-kexec-tools | May 4, 2022 | Mar 10, 2022 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Mar 9, 2022 | |
| Centos_linux | — | centos-upgrade-kexec-toolscentos-upgrade-kexec-tools-debuginfocentos-upgrade-kexec-tools-debugsource | Nov 10, 2021 | Nov 9, 2021 |
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-kexec-tools | Nov 3, 2022 | Mar 10, 2022 | |
| Oracle_linux | — | oracle-linux-upgrade-kexec-tools | Nov 17, 2021 | Mar 2, 2021 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-kexec-toolsredhat-upgrade-kexec-tools-debuginforedhat-upgrade-kexec-tools-debugsource | Nov 10, 2021 | Nov 9, 2021 | |
| Rocky_linux | rocky-upgrade-kexec-toolsrocky-upgrade-kexec-tools-debuginforocky-upgrade-kexec-tools-debugsource | Mar 12, 2024 | Mar 10, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub