Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update for grub2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: grub2 security update Advisory ID: RHSA-2023:0049-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0049 Issue date: 2023-01-09 CVE Names: CVE-2022-2601 CVE-2022-3775 ==================================================================== 1. Summary: An update for grub2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, noarch, ppc64le, x86_64 3. Description: The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices. Security Fix(es): * grub2: Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass (CVE-2022-2601) * grub2: Heap based out-of-bounds write when redering certain unicode sequences (CVE-2022-3775) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply thisupdate, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2112975 - CVE-2022-2601 grub2: Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass 2138880 - CVE-2022-3775 grub2: Heap based out-of-bounds write when redering certain unicode sequences 6. Package List: Red Hat Enterprise Linux BaseOS (v.8): Source: grub2-2.02-142.el8_7.1.src.rpm aarch64: grub2-debuginfo-2.02-142.el8_7.1.aarch64.rpm grub2-debugsource-2.02-142.el8_7.1.aarch64.rpm grub2-efi-aa64-2.02-142.el8_7.1.aarch64.rpm grub2-efi-aa64-cdboot-2.02-142.el8_7.1.aarch64.rpm grub2-tools-2.02-142.el8_7.1.aarch64.rpm grub2-tools-debuginfo-2.02-142.el8_7.1.aarch64.rpm grub2-tools-extra-2.02-142.el8_7.1.aarch64.rpm grub2-tools-extra-debuginfo-2.02-142.el8_7.1.aarch64.rpm grub2-tools-minimal-2.02-142.el8_7.1.aarch64.rpm grub2-tools-minimal-debuginfo-2.02-142.el8_7.1.aarch64.rpm noarch: grub2-common-2.02-142.el8_7.1.noarch.rpm grub2-efi-aa64-modules-2.02-142.el8_7.1.noarch.rpm grub2-efi-ia32-modules-2.02-142.el8_7.1.noarch.rpm grub2-efi-x64-modules-2.02-142.el8_7.1.noarch.rpm grub2-pc-modules-2.02-142.el8_7.1.noarch.rpm grub2-ppc64le-modules-2.02-142.el8_7.1.noarch.rpm ppc64le: grub2-debuginfo-2.02-142.el8_7.1.ppc64le.rpm grub2-debugsource-2.02-142.el8_7.1.ppc64le.rpm grub2-ppc64le-2.02-142.el8_7.1.ppc64le.rpm grub2-tools-2.02-142.el8_7.1.ppc64le.rpm grub2-tools-debuginfo-2.02-142.el8_7.1.ppc64le.rpm grub2-tools-extra-2.02-142.el8_7.1.ppc64le.rpm grub2-tools-extra-debuginfo-2.02-142.el8_7.1.ppc64le.rpm grub2-tools-minimal-2.02-142.el8_7.1.ppc64le.rpm grub2-tools-minimal-debuginfo-2.02-142.el8_7.1.ppc64le.rpm x86_64: grub2-debuginfo-2.02-142.el8_7.1.x86_64.rpm grub2-debugsource-2.02-142.el8_7.1.x86_64.rpm grub2-efi-ia32-2.02-142.el8_7.1.x86_64.rpm grub2-efi-ia32-cdboot-2.02-142.el8_7.1.x86_64.rpm grub2-efi-x64-2.02-142.el8_7.1.x86_64.rpm grub2-efi-x64-cdboot-2.02-142.el8_7.1.x86_64.rpm grub2-pc-2.02-142.el8_7.1.x86_64.rpm grub2-tools-2.02-142.el8_7.1.x86_64.rpm grub2-tools-debuginfo-2.02-142.el8_7.1.x86_64.rpm grub2-tools-efi-2.02-142.el8_7.1.x86_64.rpm grub2-tools-efi-debuginfo-2.02-142.el8_7.1.x86_64.rpm grub2-tools-extra-2.02-142.el8_7.1.x86_64.rpm grub2-tools-extra-debuginfo-2.02-142.el8_7.1.x86_64.rpm grub2-tools-minimal-2.02-142.el8_7.1.x86_64.rpm grub2-tools-minimal-debuginfo-2.02-142.el8_7.1.x86_64.rpm These packages are GPG signed by RedHat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-2601 https://access.redhat.com/security/cve/CVE-2022-3775 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY7xCGNzjgjWX9erEAQhfVA//UmW+SEsSTTHZuAyur/JEyH0ykXxhYotT v4lFD4CnQ/ITb1LuEyENRnxlrokr29ngYarZzSaQuqT8kMAqpGv+GL2l0xZ++p4p worItXQpK9ugcxQfo5gWEhCtOoKuLpjszQnOqVKOo9EiPR9htu6M9HXwpniKIesR CfwMsWcKWuecTRzYlwS54O/qO9yUwmfm6EXMpEXMEL/zHiBt49j2KJfrJh56pSvE /m/iQgooQgfGXPjMyQl0+ipdELQ+KAV+nEvhoVBTQLCzggj6MfZga3oWRiBQ7EgB c+U0THPvwjknt4e9QZV6Fo5qfu67qfBmbFf9WHOTIRf7JPCLVEcU4x1m1CyPART9 uFuzyaKK+/R5OGcyl/y2plHyIekTtZD+zYYWBQONzyiAjokdksDhPVK9G5jQTtmr 9dY3+C3jniuu2UrYsM7Xn1LWRrpDRK1hYNSdNL0A6dmWfIVf0HZ08ZVxwdAD3JL1 QihLrlDYmmfFDDF3dIYBqGKVnh40+fKMT/+fLF1c8T9AD/n3B7jJ/4Nq3cCmPPor 040rkqBxZw2XCZTc9ovsdT6v/sfVOe+Cwz2XsgtcaIT+VPlCPh0qxs0KqQkLOPW/ PMuOtmKp75T58/tQxtRrwpBI2uuPmW2zDxsjJp91GVI1f2C3mNCkn9ygd6Da/Pff lXIOLsvKmo4=Xm3K -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that solves two vulnerabilities and has two fixes is now available. . SUSE Security Update: Security update for grub2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4302-1 Rating: important References: #1205178 #1205182 #1205520 #1205554 Cross-References: CVE-2022-2601 CVE-2022-3775 CVSS scores: CVE-2022-2601 (SUSE): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2022-3775 (SUSE): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that solves two vulnerabilities and has two fixes is now available. Description: This update for grub2 fixes the following issues: Security Fixes: - CVE-2022-2601: Fixed buffer overflow in grub_font_construct_glyph (bsc#1205178). - CVE-2022-3775: Fixed integer underflow in blit_comb() (bsc#1205182). Other: - Bump upstream SBAT generation to 3 - Fix unreadable filesystem with xfs v4 superblock (bsc#1205520). - Remove zfs modules (bsc#1205554). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-4302=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-4302=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2022-4302=1 - SUSE Linux Enterprise Server 12-SP5: zypper in-t patch SUSE-SLE-SERVER-12-SP5-2022-4302=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2022-4302=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): grub2-2.02-153.1 grub2-debuginfo-2.02-153.1 grub2-debugsource-2.02-153.1 grub2-i386-pc-2.02-153.1 grub2-x86_64-efi-2.02-153.1 - SUSE OpenStack Cloud Crowbar 9 (noarch): grub2-snapper-plugin-2.02-153.1 grub2-systemd-sleep-plugin-2.02-153.1 grub2-x86_64-xen-2.02-153.1 - SUSE OpenStack Cloud 9 (noarch): grub2-snapper-plugin-2.02-153.1 grub2-systemd-sleep-plugin-2.02-153.1 grub2-x86_64-xen-2.02-153.1 - SUSE OpenStack Cloud 9 (x86_64): grub2-2.02-153.1 grub2-debuginfo-2.02-153.1 grub2-debugsource-2.02-153.1 grub2-i386-pc-2.02-153.1 grub2-x86_64-efi-2.02-153.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): grub2-2.02-153.1 grub2-debuginfo-2.02-153.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le): grub2-powerpc-ieee1275-2.02-153.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (x86_64): grub2-debugsource-2.02-153.1 grub2-i386-pc-2.02-153.1 grub2-x86_64-efi-2.02-153.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (noarch): grub2-snapper-plugin-2.02-153.1 grub2-systemd-sleep-plugin-2.02-153.1 grub2-x86_64-xen-2.02-153.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): grub2-2.02-153.1 grub2-debuginfo-2.02-153.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 s390x x86_64): grub2-debugsource-2.02-153.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64): grub2-arm64-efi-2.02-153.1 - SUSE Linux Enterprise Server 12-SP5 (ppc64le): grub2-powerpc-ieee1275-2.02-153.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): grub2-snapper-plugin-2.02-153.1 grub2-systemd-sleep-plugin-2.02-153.1 grub2-x86_64-xen-2.02-153.1 - SUSE Linux Enterprise Server 12-SP5 (x86_64): grub2-i386-pc-2.02-153.1 grub2-x86_64-efi-2.02-153.1 - SUSE Linux Enterprise Server 12-SP5 (s390x): grub2-s390x-emu-2.02-153.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): grub2-2.02-153.1 grub2-debuginfo-2.02-153.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 s390x x86_64): grub2-debugsource-2.02-153.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (ppc64le): grub2-powerpc-ieee1275-2.02-153.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64): grub2-arm64-efi-2.02-153.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (x86_64): grub2-i386-pc-2.02-153.1 grub2-x86_64-efi-2.02-153.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (noarch): grub2-snapper-plugin-2.02-153.1 grub2-systemd-sleep-plugin-2.02-153.1 grub2-x86_64-xen-2.02-153.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (s390x): grub2-s390x-emu-2.02-153.1 References: https://www.suse.com/security/cve/CVE-2022-2601.html https://www.suse.com/security/cve/CVE-2022-3775.html https://bugzilla.suse.com/1205178 https://bugzilla.suse.com/1205182 https://bugzilla.suse.com/1205520 https://bugzilla.suse.com/1205554 . Critical vulnerabilities addressed in grub2 enhance security by fixing potential buffer overflow and integer underflow risks in SUSE environments.. Linux Security Advisory, Grub2 Update, SUSE Security Fixes. . Severity: Important. LinuxSecurity.com Team
grub2 bug fix and enhancement update. \{'type': 'BugFix', 'shortCode': 'RL', 'name': 'RLBA-2021:3595', 'synopsis': 'grub2 bug fix and enhancement update', 'severity': 'UnknownSeverity', 'topic': 'An update for grub2 is now available for Rocky Linux 8.', 'description': 'The grub2 packages provide version 2 of the Grand Unified Boot Loader\n(GRUB), a highly configurable and customizable boot loader with modular\narchitecture. The packages support a variety of kernel formats, file\nsystems, computer architectures, and hardware devices.\ncausing system boot failures (BZ#1961265)', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1961265'], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHBA-2021:3595:::RHBA-2021:3595'], 'references': [], 'publishedAt': '2021-10-01T20:16:27.995301Z', 'rpms': ['grub2-2.02-99.el8_4.1.1.src.rpm', 'grub2-common-2.02-99.el8_4.1.1.noarch.rpm', 'grub2-debuginfo-2.02-99.el8_4.1.1.aarch64.rpm', 'grub2-debuginfo-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-debugsource-2.02-99.el8_4.1.1.aarch64.rpm', 'grub2-debugsource-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-efi-aa64-2.02-99.el8_4.1.1.aarch64.rpm', 'grub2-efi-aa64-cdboot-2.02-99.el8_4.1.1.aarch64.rpm', 'grub2-efi-aa64-modules-2.02-99.el8_4.1.1.noarch.rpm', 'grub2-efi-ia32-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-efi-ia32-cdboot-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-efi-ia32-modules-2.02-99.el8_4.1.1.noarch.rpm', 'grub2-efi-x64-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-efi-x64-cdboot-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-efi-x64-modules-2.02-99.el8_4.1.1.noarch.rpm', 'grub2-pc-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-pc-modules-2.02-99.el8_4.1.1.noarch.rpm', 'grub2-tools-2.02-99.el8_4.1.1.aarch64.rpm', 'grub2-tools-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-tools-debuginfo-2.02-99.el8_4.1.1.aarch64.rpm', 'grub2-tools-debuginfo-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-tools-efi-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-tools-efi-debuginfo-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-tools-extra-2.02-99.el8_4.1.1.aarch64.rpm','grub2-tools-extra-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-tools-extra-debuginfo-2.02-99.el8_4.1.1.aarch64.rpm', 'grub2-tools-extra-debuginfo-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-tools-minimal-2.02-99.el8_4.1.1.aarch64.rpm', 'grub2-tools-minimal-2.02-99.el8_4.1.1.x86_64.rpm', 'grub2-tools-minimal-debuginfo-2.02-99.el8_4.1.1.aarch64.rpm', 'grub2-tools-minimal-debuginfo-2.02-99.el8_4.1.1.x86_64.rpm']}\. A crucial new version of grub2 has been released for Rocky Linux 8, fixing boot problems. Keep your system safe!. grub2 Update, Rocky Linux Enhancement, System Boot Fix. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-9595 https://linux.oracle.com/errata/ELSA-2022-9595.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: grub2-common-2.02-123.0.7.el8_6.8.noarch.rpm grub2-efi-aa64-modules-2.02-123.0.7.el8_6.8.noarch.rpm grub2-efi-ia32-2.02-123.0.7.el8_6.8.x86_64.rpm grub2-efi-ia32-cdboot-2.02-123.0.7.el8_6.8.x86_64.rpm grub2-efi-ia32-modules-2.02-123.0.7.el8_6.8.noarch.rpm grub2-efi-x64-2.02-123.0.7.el8_6.8.x86_64.rpm grub2-efi-x64-cdboot-2.02-123.0.7.el8_6.8.x86_64.rpm grub2-efi-x64-modules-2.02-123.0.7.el8_6.8.noarch.rpm grub2-pc-2.02-123.0.7.el8_6.8.x86_64.rpm grub2-pc-modules-2.02-123.0.7.el8_6.8.noarch.rpm grub2-tools-2.02-123.0.7.el8_6.8.x86_64.rpm grub2-tools-efi-2.02-123.0.7.el8_6.8.x86_64.rpm grub2-tools-extra-2.02-123.0.7.el8_6.8.x86_64.rpm grub2-tools-minimal-2.02-123.0.7.el8_6.8.x86_64.rpm aarch64: grub2-common-2.02-123.0.7.el8_6.8.noarch.rpm grub2-efi-aa64-2.02-123.0.7.el8_6.8.aarch64.rpm grub2-efi-aa64-cdboot-2.02-123.0.7.el8_6.8.aarch64.rpm grub2-efi-aa64-modules-2.02-123.0.7.el8_6.8.noarch.rpm grub2-efi-ia32-modules-2.02-123.0.7.el8_6.8.noarch.rpm grub2-efi-x64-modules-2.02-123.0.7.el8_6.8.noarch.rpm grub2-pc-modules-2.02-123.0.7.el8_6.8.noarch.rpm grub2-tools-2.02-123.0.7.el8_6.8.aarch64.rpm grub2-tools-extra-2.02-123.0.7.el8_6.8.aarch64.rpm grub2-tools-minimal-2.02-123.0.7.el8_6.8.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/grub2-2.02-123.0.7.el8_6.8.src.rpm Related CVEs: CVE-2022-28737 CVE-2021-3696 CVE-2022-28734 CVE-2021-3695 CVE-2021-3697 CVE-2022-28733 CVE-2022-28735 CVE-2022-28736 Description of changes: [2.02-123.0.7.el8_6.8] - Enable back btrfs module by default [Orabug: 34377188] [2.02-123.0.6.el8_6.8] - Backport upstream SNP protocol fixes [Orabug: 34195100] [2.02-123.0.5.el8_6.8] - Rebase Fix EFI loader kernel image allocation patch, adapt it to new NX code[Orabug: 34352232] [2.02-123.0.4.el8_6.8] - enable multiboot2 [Orabug: 34285558] - backport arm64: Fix EFI loader kernel image allocation [Orabug: 33702462] - backport Arm: check for the PE magic for the compiled arch [Orabug: 33702462] - Backport some better script logic for BTRFS support [Orabug: 32448171] - Do not add shim and grub certificate deps for aarch64 packages [Orabug: 32670033] - Update Oracle SBAT data [Orabug: 32670033] - Use new signing certificate [Orabug: 32670033] - Fix various coverity issues [Orabug: 32530657] - Set proper blsdir if /boot is on btrfs rootfs [Orabug: 32063327] - Add CVE-2020-15706, CVE-2020-15707 to the list [Orabug: 31225072] - honor /etc/sysconfig/kernel DEFAULTKERNEL setting for BLS [Orabug: 30643497] - set EFIDIR as redhat for additional grub2 tools [Orabug: 29875597] - Update upstream references [Orabug: 26388226] - Insert Unbreakable Enterprise Kernel text into BLS config file [Orabug: 29417955] - fix symlink removal scriptlet, to be executed only on removal [Orabug: 19231481] - Fix comparison in patch for 18504756 - Remove symlink to grub environment file during uninstall on EFI platforms [Orabug: 19231481] - Put "with" in menuentry instead of "using" [Orabug: 18504756] - Use different titles for UEK and RHCK kernels [Orabug: 18504756] [2.06-123.el8_6.8] - CVE fixes for 2022-06-07 - CVE-2022-28736 CVE-2022-28735 CVE-2022-28734 CVE-2022-28733 - CVE-2021-3697 CVE-2021-3696 CVE-2021-3695 - Resolves: #2031899 _______________________________________________ El-errata mailing list
CVE fixes for 2022-06-06 Includes: CVE-2022-28736 CVE-2022-28735 CVE-2022-28734 CVE-2022-28733 CVE-2021-3697 CVE-2021-3696 CVE-2021-3695 Moderate/high, some network access. Update! Upstream disclosure with more information: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-9b4f9af4ce 2022-06-22 01:24:44.434639 --------------------------------------------------------------------------------Name : grub2 Product : Fedora 35 Version : 2.06 Release : 11.fc35 URL : Summary : Bootloader with support for Linux, Multiboot and more Description : The GRand Unified Bootloader (GRUB) is a highly configurable and customizable bootloader with modular architecture. It supports a rich variety of kernel formats, file systems, computer architectures and hardware devices. --------------------------------------------------------------------------------Update Information: CVE fixes for 2022-06-06 Includes: CVE-2022-28736 CVE-2022-28735 CVE-2022-28734 CVE-2022-28733 CVE-2021-3697 CVE-2021-3696 CVE-2021-3695 Moderate/high, some network access. Update! Upstream disclosure with more information: --------------------------------------------------------------------------------ChangeLog: * Thu May 12 2022 Robbie Harwood - 1:2.06-11 - CVE fixes for 2022-05-24 - Resolves: CVE-2022-28736 CVE-2022-28735 CVE-2022-28734 CVE-2022-28733 - Resolves: CVE-2021-3697 CVE-2021-3696 CVE-2021-3695 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-9b4f9af4ce' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for grub2, mokutil, shim, and shim-unsigned-x64 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: grub2, mokutil, shim, and shim-unsigned-x64 security update Advisory ID: RHSA-2022:5095-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:5095 Issue date: 2022-06-16 CVE Names: CVE-2021-3695 CVE-2021-3696 CVE-2021-3697 CVE-2022-28733 CVE-2022-28734 CVE-2022-28735 CVE-2022-28736 CVE-2022-28737 ==================================================================== 1. Summary: An update for grub2, mokutil, shim, and shim-unsigned-x64 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, noarch, ppc64le, x86_64 3. Description: The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices. The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments. Security Fix(es): * grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733) * grub2: Crafted PNG grayscale images maylead to out-of-bounds write in heap (CVE-2021-3695) * grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling (CVE-2021-3696) * grub2: Crafted JPEG image can lead to buffer underflow write in the heap (CVE-2021-3697) * grub2: Out-of-bound write when handling split HTTP headers(CVE-2022-28734) * grub2: shim_lock verifier allows non-kernel files to be loaded (CVE-2022-28735) * grub2: use-after-free in grub_cmd_chainloader() (CVE-2022-28736) * shim: Buffer overflow when loading crafted EFI images (CVE-2022-28737) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1991685 - CVE-2021-3695 grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap 1991686 - CVE-2021-3696 grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling 1991687 - CVE-2021-3697 grub2: Crafted JPEG image can lead to buffer underflow write in the heap 2083339 - CVE-2022-28733 grub2: Integer underflow in grub_net_recv_ip4_packets 2090463 - CVE-2022-28734 grub2: Out-of-bound write when handling split HTTP headers2090857 - CVE-2022-28735 grub2: shim_lock verifier allows non-kernel files to be loaded 2090899 - CVE-2022-28737 shim: Buffer overflow when loading crafted EFI images 2092613 - CVE-2022-28736 grub2: use-after-free in grub_cmd_chainloader() 6. Package List: Red Hat Enterprise Linux BaseOS (v.8): Source: grub2-2.02-123.el8_6.8.src.rpm mokutil-0.3.0-11.el8_6.1.src.rpm shim-15.6-1.el8.src.rpm aarch64: grub2-debuginfo-2.02-123.el8_6.8.aarch64.rpm grub2-debugsource-2.02-123.el8_6.8.aarch64.rpm grub2-efi-aa64-2.02-123.el8_6.8.aarch64.rpm grub2-efi-aa64-cdboot-2.02-123.el8_6.8.aarch64.rpm grub2-tools-2.02-123.el8_6.8.aarch64.rpm grub2-tools-debuginfo-2.02-123.el8_6.8.aarch64.rpm grub2-tools-extra-2.02-123.el8_6.8.aarch64.rpm grub2-tools-extra-debuginfo-2.02-123.el8_6.8.aarch64.rpm grub2-tools-minimal-2.02-123.el8_6.8.aarch64.rpm grub2-tools-minimal-debuginfo-2.02-123.el8_6.8.aarch64.rpm mokutil-0.3.0-11.el8_6.1.aarch64.rpm mokutil-debuginfo-0.3.0-11.el8_6.1.aarch64.rpm mokutil-debugsource-0.3.0-11.el8_6.1.aarch64.rpm shim-aa64-15.6-1.el8.aarch64.rpm noarch: grub2-common-2.02-123.el8_6.8.noarch.rpm grub2-efi-aa64-modules-2.02-123.el8_6.8.noarch.rpm grub2-efi-ia32-modules-2.02-123.el8_6.8.noarch.rpm grub2-efi-x64-modules-2.02-123.el8_6.8.noarch.rpm grub2-pc-modules-2.02-123.el8_6.8.noarch.rpm grub2-ppc64le-modules-2.02-123.el8_6.8.noarch.rpm ppc64le: grub2-debuginfo-2.02-123.el8_6.8.ppc64le.rpm grub2-debugsource-2.02-123.el8_6.8.ppc64le.rpm grub2-ppc64le-2.02-123.el8_6.8.ppc64le.rpm grub2-tools-2.02-123.el8_6.8.ppc64le.rpm grub2-tools-debuginfo-2.02-123.el8_6.8.ppc64le.rpm grub2-tools-extra-2.02-123.el8_6.8.ppc64le.rpm grub2-tools-extra-debuginfo-2.02-123.el8_6.8.ppc64le.rpm grub2-tools-minimal-2.02-123.el8_6.8.ppc64le.rpm grub2-tools-minimal-debuginfo-2.02-123.el8_6.8.ppc64le.rpm x86_64: grub2-debuginfo-2.02-123.el8_6.8.x86_64.rpm grub2-debugsource-2.02-123.el8_6.8.x86_64.rpm grub2-efi-ia32-2.02-123.el8_6.8.x86_64.rpm grub2-efi-ia32-cdboot-2.02-123.el8_6.8.x86_64.rpm grub2-efi-x64-2.02-123.el8_6.8.x86_64.rpm grub2-efi-x64-cdboot-2.02-123.el8_6.8.x86_64.rpm grub2-pc-2.02-123.el8_6.8.x86_64.rpm grub2-tools-2.02-123.el8_6.8.x86_64.rpm grub2-tools-debuginfo-2.02-123.el8_6.8.x86_64.rpm grub2-tools-efi-2.02-123.el8_6.8.x86_64.rpm grub2-tools-efi-debuginfo-2.02-123.el8_6.8.x86_64.rpm grub2-tools-extra-2.02-123.el8_6.8.x86_64.rpm grub2-tools-extra-debuginfo-2.02-123.el8_6.8.x86_64.rpm grub2-tools-minimal-2.02-123.el8_6.8.x86_64.rpm grub2-tools-minimal-debuginfo-2.02-123.el8_6.8.x86_64.rpm mokutil-0.3.0-11.el8_6.1.x86_64.rpm mokutil-debuginfo-0.3.0-11.el8_6.1.x86_64.rpm mokutil-debugsource-0.3.0-11.el8_6.1.x86_64.rpm shim-ia32-15.6-1.el8.x86_64.rpm shim-x64-15.6-1.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v. 8): Source: shim-unsigned-x64-15.6-1.el8.src.rpm x86_64: shim-unsigned-x64-15.6-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-3695 https://access.redhat.com/security/cve/CVE-2021-3696 https://access.redhat.com/security/cve/CVE-2021-3697 https://access.redhat.com/security/cve/CVE-2022-28733 https://access.redhat.com/security/cve/CVE-2022-28734 https://access.redhat.com/security/cve/CVE-2022-28735 https://access.redhat.com/security/cve/CVE-2022-28736 https://access.redhat.com/security/cve/CVE-2022-28737 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYqtvddzjgjWX9erEAQjRmQ//YE4WPGQT/7En15s+P3gscZDFMMvLZO6n c6TqQorOIBmx+WHBSfMWapMLDQnaIZYnKhmou9I64Je03jA3oNXFNuzTRFvLm3hF Ly8+zU+Asv18WBRLIcDCZ70xgguSrHj/LlnkOnJhOQvi2el/40hDxxG2ohWsg6UQ tgZ8PZN4UWoihTCPVwlMnhsOI96UtILm5BqIP1ZmRzYHaOVeQcN/00qq5S6otDKv iKFEfP+SSaz4cU9t0ckOnGAPe9Fpez5Rk9v4jURwGdBf65CONfSQSoiUXdy1ikjd 3mCdmMJF6YmqEYWvw663qd6CVkj1N7qDklVc/oXpJacrE9b78O5u6p7M7HOXlfDH Gj2nwKwRAdYsnbvW+5kw59rRdmOCe/57jnPen4kkEWMh7dg3yn7b870LS3SUpFwG enqHdZC8U4w85Wp5GMuUi+EPYy9Gh7OTmuFUFBJeI1NJjQd7I1XgpcyAoxqFnwFO n77fTxDDbMJldP9yZbIvztLOEA/BFNZNl3FrAMlutBCweJyCaAnzWhdkeHM+7y/k S2e0gsh4jwTtOuHs2S7XZ8mzzePaJVgQ7SRG6t8jMaA05duuNniIAJEKVFYRGgsw aqzSpTAGVxiFPQ2wzYJHFbtyhhSZtRRhNaSpbI0uNj7aztnyjEofX3qMh1B3Wx4r RLkWjRXdZrE=q0Jp -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for grub2, mokutil, and shim is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: grub2, mokutil, and shim security update Advisory ID: RHSA-2022:5098-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:5098 Issue date: 2022-06-16 CVE Names: CVE-2021-3695 CVE-2021-3696 CVE-2021-3697 CVE-2022-28733 CVE-2022-28734 CVE-2022-28735 CVE-2022-28736 CVE-2022-28737 ==================================================================== 1. Summary: An update for grub2, mokutil, and shim is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS E4S (v. 8.1) - aarch64, noarch, ppc64le, x86_64 3. Description: The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices. The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments. Security Fix(es): * grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733) * grub2: Crafted PNG grayscale images may lead to out-of-bounds writein heap (CVE-2021-3695) * grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling (CVE-2021-3696) * grub2: Crafted JPEG image can lead to buffer underflow write in the heap (CVE-2021-3697) * grub2: Out-of-bound write when handling split HTTP headers(CVE-2022-28734) * grub2: shim_lock verifier allows non-kernel files to be loaded (CVE-2022-28735) * grub2: use-after-free in grub_cmd_chainloader() (CVE-2022-28736) * shim: Buffer overflow when loading crafted EFI images (CVE-2022-28737) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1991685 - CVE-2021-3695 grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap 1991686 - CVE-2021-3696 grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling 1991687 - CVE-2021-3697 grub2: Crafted JPEG image can lead to buffer underflow write in the heap 2083339 - CVE-2022-28733 grub2: Integer underflow in grub_net_recv_ip4_packets 2090463 - CVE-2022-28734 grub2: Out-of-bound write when handling split HTTP headers2090857 - CVE-2022-28735 grub2: shim_lock verifier allows non-kernel files to be loaded 2090899 - CVE-2022-28737 shim: Buffer overflow when loading crafted EFI images 2092613 - CVE-2022-28736 grub2: use-after-free in grub_cmd_chainloader() 6. Package List: Red Hat Enterprise Linux BaseOS E4S (v.8.1): Source: grub2-2.02-87.el8_1.10.src.rpm mokutil-0.3.0-9.el8_1.1.src.rpm shim-15.6-1.el8.src.rpm aarch64: grub2-debuginfo-2.02-87.el8_1.10.aarch64.rpm grub2-debugsource-2.02-87.el8_1.10.aarch64.rpm grub2-efi-aa64-2.02-87.el8_1.10.aarch64.rpm grub2-efi-aa64-cdboot-2.02-87.el8_1.10.aarch64.rpm grub2-tools-2.02-87.el8_1.10.aarch64.rpm grub2-tools-debuginfo-2.02-87.el8_1.10.aarch64.rpm grub2-tools-extra-2.02-87.el8_1.10.aarch64.rpm grub2-tools-extra-debuginfo-2.02-87.el8_1.10.aarch64.rpm grub2-tools-minimal-2.02-87.el8_1.10.aarch64.rpm grub2-tools-minimal-debuginfo-2.02-87.el8_1.10.aarch64.rpm mokutil-0.3.0-9.el8_1.1.aarch64.rpm mokutil-debuginfo-0.3.0-9.el8_1.1.aarch64.rpm mokutil-debugsource-0.3.0-9.el8_1.1.aarch64.rpm shim-aa64-15.6-1.el8.aarch64.rpm noarch: grub2-common-2.02-87.el8_1.10.noarch.rpm grub2-efi-aa64-modules-2.02-87.el8_1.10.noarch.rpm grub2-efi-ia32-modules-2.02-87.el8_1.10.noarch.rpm grub2-efi-x64-modules-2.02-87.el8_1.10.noarch.rpm grub2-pc-modules-2.02-87.el8_1.10.noarch.rpm grub2-ppc64le-modules-2.02-87.el8_1.10.noarch.rpm ppc64le: grub2-debuginfo-2.02-87.el8_1.10.ppc64le.rpm grub2-debugsource-2.02-87.el8_1.10.ppc64le.rpm grub2-ppc64le-2.02-87.el8_1.10.ppc64le.rpm grub2-tools-2.02-87.el8_1.10.ppc64le.rpm grub2-tools-debuginfo-2.02-87.el8_1.10.ppc64le.rpm grub2-tools-extra-2.02-87.el8_1.10.ppc64le.rpm grub2-tools-extra-debuginfo-2.02-87.el8_1.10.ppc64le.rpm grub2-tools-minimal-2.02-87.el8_1.10.ppc64le.rpm grub2-tools-minimal-debuginfo-2.02-87.el8_1.10.ppc64le.rpm x86_64: grub2-debuginfo-2.02-87.el8_1.10.x86_64.rpm grub2-debugsource-2.02-87.el8_1.10.x86_64.rpm grub2-efi-ia32-2.02-87.el8_1.10.x86_64.rpm grub2-efi-ia32-cdboot-2.02-87.el8_1.10.x86_64.rpm grub2-efi-x64-2.02-87.el8_1.10.x86_64.rpm grub2-efi-x64-cdboot-2.02-87.el8_1.10.x86_64.rpm grub2-pc-2.02-87.el8_1.10.x86_64.rpm grub2-tools-2.02-87.el8_1.10.x86_64.rpm grub2-tools-debuginfo-2.02-87.el8_1.10.x86_64.rpm grub2-tools-efi-2.02-87.el8_1.10.x86_64.rpm grub2-tools-efi-debuginfo-2.02-87.el8_1.10.x86_64.rpm grub2-tools-extra-2.02-87.el8_1.10.x86_64.rpm grub2-tools-extra-debuginfo-2.02-87.el8_1.10.x86_64.rpm grub2-tools-minimal-2.02-87.el8_1.10.x86_64.rpm grub2-tools-minimal-debuginfo-2.02-87.el8_1.10.x86_64.rpm mokutil-0.3.0-9.el8_1.1.x86_64.rpm mokutil-debuginfo-0.3.0-9.el8_1.1.x86_64.rpm mokutil-debugsource-0.3.0-9.el8_1.1.x86_64.rpm shim-ia32-15.6-1.el8.x86_64.rpm shim-x64-15.6-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-3695 https://access.redhat.com/security/cve/CVE-2021-3696 https://access.redhat.com/security/cve/CVE-2021-3697 https://access.redhat.com/security/cve/CVE-2022-28733 https://access.redhat.com/security/cve/CVE-2022-28734 https://access.redhat.com/security/cve/CVE-2022-28735 https://access.redhat.com/security/cve/CVE-2022-28736 https://access.redhat.com/security/cve/CVE-2022-28737 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYqtvZtzjgjWX9erEAQiqow/+IcUOf0BCPaIaF7Wfx3FzqT1UPNeHz7oe OIN8sDIpQAQRnNC7abh4Y10xZY/iBq9KzGMllLI95J680QeAsfRGHI/FOuAjE8mH dFDFjJPf368OCBlucD4ER3bOh/Z8qmCtiL+udaiXI3tOn9v2jCyAZU5l6XLkUMmM rwTSNejOkLFlZZSbOvsj7HPGovvSRwaeWyP8HSsB/x8ZxATV9hnWFxgzPShdc4Av Guo+e5Ox5kCsYUMx+JaLTB5f0r84Ww/JF/yC54+7GaJjKqfOn/fBZve6x8EpMlzH p6hiYoc0H3w4Q8dt64Dy84YBxd2lab1yf78P6wnfIc8DbJLk8WEiGFHXgztUcoSF zPHzy3KvdRjm0VbsHv6zos+vw6xk853lk7x1VC+hfzwX8k+v6qjLQVWe6o0Bgbr1 uddxC4FS8q9IimrBIOdQMFgAB2EHlkQ6+rtAMEnrQl7FNuc+01bfqAzlSxST5whA tmDHTn+yfAq8IZxme9fUB0IWPE6B7X9BuFOEUJXoDA7a32XNBh7rxZMKM8Qvik2m f6wFbeOMUP1qH5aI5q7w7gjDALZYCjkm6G4PZIzPe7b5d776oVTi6LVLrNqoF3iS YSoJcfgbAD/z4vhD7+v8jchsKajLhfU6cg1Y55tCaWE+ChZX5gxxg9np2RimQUKg OSDo4rO0XWs=U5j2 -----END PGP SIGNATURE----- -- RHSA-announce mailinglist
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-9471 https://linux.oracle.com/errata/ELSA-2022-9471.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: grub2-common-2.02-123.0.3.el8.noarch.rpm grub2-efi-aa64-modules-2.02-123.0.3.el8.noarch.rpm grub2-efi-ia32-2.02-123.0.3.el8.x86_64.rpm grub2-efi-ia32-cdboot-2.02-123.0.3.el8.x86_64.rpm grub2-efi-ia32-modules-2.02-123.0.3.el8.noarch.rpm grub2-efi-x64-2.02-123.0.3.el8.x86_64.rpm grub2-efi-x64-cdboot-2.02-123.0.3.el8.x86_64.rpm grub2-efi-x64-modules-2.02-123.0.3.el8.noarch.rpm grub2-pc-2.02-123.0.3.el8.x86_64.rpm grub2-pc-modules-2.02-123.0.3.el8.noarch.rpm grub2-tools-2.02-123.0.3.el8.x86_64.rpm grub2-tools-efi-2.02-123.0.3.el8.x86_64.rpm grub2-tools-extra-2.02-123.0.3.el8.x86_64.rpm grub2-tools-minimal-2.02-123.0.3.el8.x86_64.rpm aarch64: grub2-common-2.02-123.0.3.el8.noarch.rpm grub2-efi-aa64-2.02-123.0.3.el8.aarch64.rpm grub2-efi-aa64-cdboot-2.02-123.0.3.el8.aarch64.rpm grub2-efi-aa64-modules-2.02-123.0.3.el8.noarch.rpm grub2-efi-ia32-modules-2.02-123.0.3.el8.noarch.rpm grub2-efi-x64-modules-2.02-123.0.3.el8.noarch.rpm grub2-pc-modules-2.02-123.0.3.el8.noarch.rpm grub2-tools-2.02-123.0.3.el8.aarch64.rpm grub2-tools-extra-2.02-123.0.3.el8.aarch64.rpm grub2-tools-minimal-2.02-123.0.3.el8.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/grub2-2.02-123.0.3.el8.src.rpm Related CVEs: CVE-2021-3695 CVE-2021-3696 CVE-2021-3697 CVE-2022-28733 CVE-2022-28734 CVE-2022-28735 CVE-2022-28736 Description of changes: [2.02-123.0.3] - Add CVE-2022-28736 to the list [JIRA: OLDIS-16371] [2.02-123.0.2] - Fix: CVE-2021-3695, CVE-2021-3696, CVE-2021-3697, CVE-2022-28733, CVE-2022-28734, CVE-2022-28735 [JIRA: OLDIS-16371] - Various coverity fixes [JIRA: OLDIS-16371] - bump SBAT generation _______________________________________________ El-errata mailinglist
Get the latest Linux and open source security news straight to your inbox.