Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Oracle Linux 7 ELSA-2023-12952 Important Grub2 Security Update

oracle
Calendar Grey November 13, 2023
Oracle Linux Logo Esm H88
Oracle Linux 7 Security Patch ELSA-2023-12952 for grub2 tackles significant vulnerabilities. Examine the modifications and enhancements implemented.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

[2.02-0.87.0.26.el7_9.9] - Enable common subpackage for aarch64 - Do not sign aarch64 efi binaries [Orabug: 32670043] - Remove aarch64 deps on shim [Orabug: 32670043] - Restore versioned certificate provide for aarch64 package to satisfy shim [Orabug: 32670043] [2.02-0.87.0.24.el7_9.9] - Replace bugzilla.oracle.com reference [Orabug: 35477723] [2.02-0.87.0.23.el7_9.9] - Backport kernel EFI allocation pacthes [Orabug: 34301086] [2.02-0.87.0.21.el7_9.9] - Add CVE-2022-28736 to the list [JIRA: OLDIS-16371] [2.02-0.87.0.19.el7_9.9] - Fix: CVE-2021-3695, CVE-2021-3696, CVE-2021-3697, CVE-2022-28733, CVE-2022-28734, CVE-2022-28735 [JIRA: OLDIS-16371] - Various coverity fixes [JIRA: OLDIS-16371] - bump SBAT generation [JIRA: OLDIS-16371] [2.02-0.87.0.17.el7_9.9] - Cleanup XEN shell script (Alex Burmashev) [Orabug: 33851417] - Update SBAT data (Alex Burmashev) [Orabug: 33851417] - efinet: change SNP open call (Alex Burmashev) [Orabug: 32646964] - disable buggy 0183-efinet-retransmit...

Read the Full Advisory

SRPMs

https://oss.oracle.com:443/ol7/SRPMS-updates//grub2-2.02-0.87.0.26.el7_9.9.src.rpm

x86_64

aarch64

grub2-2.02-0.87.0.26.el7_9.9.aarch64.rpm grub2-common-2.02-0.87.0.26.el7_9.9.noarch.rpm grub2-efi-aa64-2.02-0.87.0.26.el7_9.9.aarch64.rpm grub2-efi-aa64-cdboot-2.02-0.87.0.26.el7_9.9.aarch64.rpm grub2-efi-aa64-modules-2.02-0.87.0.26.el7_9.9.noarch.rpm grub2-tools-2.02-0.87.0.26.el7_9.9.aarch64.rpm grub2-tools-extra-2.02-0.87.0.26.el7_9.9.aarch64.rpm grub2-tools-minimal-2.02-0.87.0.26.el7_9.9.aarch64.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2022-28733 CVE-2022-28734 CVE-2022-28735 CVE-2022-28736 CVE-2021-3695 CVE-2021-3696 CVE-2021-3697

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here