gpp_maybe
Security update for grub2
SUSE-SLE-Module-Server-Applications-15-SP2-2021-683
This update for grub2 fixes the following issues: grub2 implements the new "SBAT" method for SHIM based secure boot revocation. (bsc#1182057) - CVE-2020-25632: Fixed a use-after-free in rmmod command (bsc#1176711) - CVE-2020-25647: Fixed an out-of-bound write in grub_usb_device_initialize() (bsc#1177883) - CVE-2020-27749: Fixed a stack buffer overflow in grub_parser_split_cmdline (bsc#1179264) - CVE-2020-27779, CVE-2020-14372: Disallow cutmem and acpi commands in secure boot mode (bsc#1179265 bsc#1175970) - CVE-2021-20225: Fixed a heap out-of-bounds write in short form option parser (bsc#1182262) - CVE-2021-20233: Fixed a heap out-of-bound write due to mis-calculation of space required for quoting (bsc#1182263)
-
Release DateMar 2 2021
-
ReferencesBugzilla: 1175970, 1177883, 1179264, 1182057, 1182263, 1176711, 1182262, 1179265
CVEs: CVE-2020-27749, CVE-2020-27779, CVE-2020-14372, CVE-2020-25632, CVE-2021-20233, CVE-2021-20225, CVE-2020-25647 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Server Applications Module 15.2 x86_64
-
Packagesgrub2
Bootloader with support for Linux, Multiboot and moregrub2-x86_64-xen2.04-9.34.1 lock src
Bootloader with support for Linux, Multiboot and more2.04-9.34.1 lock rpm