security advisorycriticalsoftware update
Maxim Suhanov discovered multiple vulnerabilities in GURB2's code to handle NTFS filesystems, which may result in a Secure Boot bypass. For the oldstable distribution (bullseye), these problems have been fixed . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5519-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso October 06, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : grub2 CVE ID : CVE-2023-4692 CVE-2023-4693 Maxim Suhanov discovered multiple vulnerabilities in GURB2's code to handle NTFS filesystems, which may result in a Secure Boot bypass. For the oldstable distribution (bullseye), these problems have been fixed in version 2.06-3~deb11u6. For the stable distribution (bookworm), these problems have been fixed in version 2.06-13+deb12u1. We recommend that you upgrade your grub2 packages. For the detailed security status of grub2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/grub2 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian security notice DSA-5520-1 concerns vulnerabilities in systemd that might allow privilege escalation. Upgrade is advised.. Debian Security, Grub2 Issues, Secure Boot Bypass, NTFS Security, Software Update. . Severity: Critical. LinuxSecurity.com Team
Oct 06, 2023
•Critical
Debian