Multiple vulnerabilities have been discovered in GRUB, the worst of which may allow for secureboot bypass.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202209-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: GRUB: Multiple Vulnerabilities Date: September 25, 2022 Bugs: #850535, #835082 ID: 202209-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in GRUB, the worst of which may allow for secureboot bypass. Background ========= GNU GRUB is a multiboot boot loader used by most Linux systems. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-boot/grub < 2.06 > = 2.06 Description ========== Multiple vulnerabilities have been discovered in GRUB. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All GRUB users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-boot/grub-2.06-r3" After upgrading, make sure to run the grub-install command with options appropriate for your system. See the GRUB2 Gentoo Wiki page for directions. Your system will be vulnerable until this action is performed. References ========= [ 1 ] CVE-2021-3695 https://nvd.nist.gov/vuln/detail/CVE-2021-3695 [ 2 ] CVE-2021-3696 https://nvd.nist.gov/vuln/detail/CVE-2021-3696 [ 3 ]CVE-2021-3697 https://nvd.nist.gov/vuln/detail/CVE-2021-3697 [ 4 ] CVE-2021-3981 https://nvd.nist.gov/vuln/detail/CVE-2021-3981 [ 5 ] CVE-2022-28733 https://nvd.nist.gov/vuln/detail/CVE-2022-28733 [ 6 ] CVE-2022-28734 https://nvd.nist.gov/vuln/detail/CVE-2022-28734 [ 7 ] CVE-2022-28735 https://nvd.nist.gov/vuln/detail/CVE-2022-28735 [ 8 ] CVE-2022-28736 https://nvd.nist.gov/vuln/detail/CVE-2022-28736 [ 9 ] CVE-2022-28737 https://nvd.nist.gov/vuln/detail/CVE-2022-28737 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202209-12 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
* License is now BSD-2-Clause-Patent * Re-enable secureboot enrollment * Use qemu-ovmf-secureboot from git. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-d47a9d4b8b 2019-08-15 18:07:56.659780 --------------------------------------------------------------------------------Name : edk2 Product : Fedora 30 Version : 20190501stable Release : 2.fc30 URL : https://www.tianocore.org/edk2/ Summary : EFI Development Kit II Description : EDK II is a development code base for creating UEFI drivers, applications and firmware images. --------------------------------------------------------------------------------Update Information: * License is now BSD-2-Clause-Patent * Re-enable secureboot enrollment * Use qemu-ovmf-secureboot from git --------------------------------------------------------------------------------ChangeLog: * Mon Jul 15 2019 Cole Robinson - 20190501stable-2 - License is now BSD-2-Clause-Patent - Re-enable secureboot enrollment - Use qemu-ovmf-secureboot from git * Thu Jul 11 2019 Cole Robinson - 20190501stable-1 - Update to stable-201905 - Update to openssl-1.1.1b - Ship VARS file for ovmf-ia32 (bug 1688596) - Ship Fedora-variant JSON "firmware descriptor files" - Resolves rhbz#1728652 --------------------------------------------------------------------------------References: [ 1 ] Bug #1728652 - RFE: Ship the JSON firmware "descriptor files" as part of EDK2 https://bugzilla.redhat.com/show_bug.cgi?id=1728652 [ 2 ] Bug #1688596 - edk2-ovmf-ia32 is missing OVMF_VARS https://bugzilla.redhat.com/show_bug.cgi?id=1688596 [ 3 ] Bug #1701710 - VM turns on, uses a lot of CPU, uses almost no memory, indefinite black console screen https://bugzilla.redhat.com/show_bug.cgi?id=1701710 [ 4 ] Bug #1694085 - CVE-2018-12179 CVE-2018-12182 CVE-2018-12183 CVE-2019-0161 edk2: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1694085 [ 5 ] Bug #1691645 - CVE-2019-0160 edk2: buffer overflows in PartitionDxe and UdfDxe with long file names and invalid UDF media [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1691645 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-d47a9d4b8b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.