Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2025:01961-1 critical: updates for grub2 vulnerabilities

suse
Calendar Grey June 16, 2025
Dist Suse Esm H88
Critical SUSE update for grub2 resolves multiple vulnerabilities. Install patch for secure systems and avoid exploits.
* bsc#1215935 * bsc#1215936 * bsc#1233606 * bsc#1233608 * bsc#1233609

Summary

## This update for grub2 fixes the following issues: * CVE-2023-4692: nfs: out-of-bounds write at fs/ntfs.c may lead to unsigned code execution (bsc#1215935). * CVE-2023-4693: nfs: out-of-bounds read at fs/ntfs.c (bsc#1215936). * CVE-2024-45774: heap overflows in JPEG parser (bsc#1233609). * CVE-2024-45775: missing NULL check in extcmd parser (bsc#1233610). * CVE-2024-45776: overflow in .MO file (gettext) handling (bsc#1233612). * CVE-2024-45777: integer overflow in gettext (bsc#1233613). * CVE-2024-45778: bfs filesystem not fuzzing stable (bsc#1233606). * CVE-2024-45779: bfs: heap overflow (bsc#1233608). * CVE-2024-45780: overflow in tar/cpio (bsc#1233614). * CVE-2024-45781: ufs: strcpy overflow (bsc#1233617). * CVE-2024-45782: hfs: strcpy overflow (bsc#1233615).

References

* bsc#1215935

* bsc#1215936

* bsc#1233606

* bsc#1233608

* bsc#1233609

* bsc#1233610

* bsc#1233612

* bsc#1233613

* bsc#1233614

* bsc#1233615

* bsc#1233616

* bsc#1233617

* bsc#1234958

* bsc#1236316

* bsc#1236317

* bsc#1237002

* bsc#1237006

* bsc#1237008

* bsc#1237009

* bsc#1237010

* bsc#1237011

* bsc#1237012

* bsc#1237013

* bsc#1237014

Cross-

* CVE-2023-4692

* CVE-2023-4693

* CVE-2024-45774

* CVE-2024-45775

* CVE-2024-45776

* CVE-2024-45777

* CVE-2024-45778

* CVE-2024-45779

* CVE-2024-45780

* CVE-2024-45781

* CVE-2024-45782

* CVE-2024-45783

* CVE-2024-56737

* CVE-2025-0622

* CVE-2025-0624

* CVE-2025-0677

* CVE-2025-0678

* CVE-2025-0684

* CVE-2025-0685

* CVE-2025-0686

* CVE-2025-0689

* CVE-2025-0690

* CVE-2025-1118

* CVE-2025-1125

CVSS scores:

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:01961-1
Release Date: 2025-06-16T10:03:23Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here