CVE-2019-14865: GNU GRUB2

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.

Affected products

  • GNU GRUB2: affected versions not specified

Published 2019-11-29. Last modified 2026-06-17.