https://bugzilla.redhat.com/show_bug.cgi?id=2223437 The "/boot/efi/EFI/fedora/grub.cfg" configuration file allows an unprivileged user with physical access to a computer to bypass the GRUB password protection feature on many (but not all) UEFI-based systems.
Created grub2 tracking bugs for this issue: Affects: fedora-all [bug 2258096]
Please add to the doc text that users should remove the stub grub.cfg in their ESP: # rm /boot/efi/EFI/redhat/grub.cfg before they do the update, so that it is regenerated with the correct search flags during the update.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2024:0437 https://access.redhat.com/errata/RHSA-2024:0437
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:0468 https://access.redhat.com/errata/RHSA-2024:0468
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:0456 https://access.redhat.com/errata/RHSA-2024:0456