Relax-and-Recover is a setup-and-forget Linux bare metal disaster recovery solution. It is easy to set up and requires no maintenance so there is no excuse for not using it.
Security Fix(es):
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.(CVE-2024-23301)
{ "severity": "High" }
{ "src": [ "rear-2.4-5.oe2203.src.rpm", "rear-2.4-5.oe2203sp1.src.rpm", "rear-2.4-5.oe2203sp2.src.rpm", "rear-2.4-5.oe2203sp3.src.rpm" ], "x86_64": [ "rear-2.4-5.oe2203.x86_64.rpm", "rear-2.4-5.oe2203sp1.x86_64.rpm", "rear-2.4-5.oe2203sp2.x86_64.rpm", "rear-2.4-5.oe2203sp3.x86_64.rpm" ], "noarch": [ "rear-help-2.4-5.oe2203.noarch.rpm", "rear-help-2.4-5.oe2203sp1.noarch.rpm", "rear-help-2.4-5.oe2203sp2.noarch.rpm", "rear-help-2.4-5.oe2203sp3.noarch.rpm" ] }