Relax-and-Recover is a setup-and-forget Linux bare metal disaster recovery solution. It is easy to set up and requires no maintenance so there is no excuse for not using it.
Security Fix(es):
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.(CVE-2024-23301)
{
"severity": "High"
}{
"x86_64": [
"rear-2.4-5.oe2203.x86_64.rpm",
"rear-2.4-5.oe2203sp1.x86_64.rpm",
"rear-2.4-5.oe2203sp2.x86_64.rpm",
"rear-2.4-5.oe2203sp3.x86_64.rpm"
],
"src": [
"rear-2.4-5.oe2203.src.rpm",
"rear-2.4-5.oe2203sp1.src.rpm",
"rear-2.4-5.oe2203sp2.src.rpm",
"rear-2.4-5.oe2203sp3.src.rpm"
],
"noarch": [
"rear-help-2.4-5.oe2203.noarch.rpm",
"rear-help-2.4-5.oe2203sp1.noarch.rpm",
"rear-help-2.4-5.oe2203sp2.noarch.rpm",
"rear-help-2.4-5.oe2203sp3.noarch.rpm"
]
}