gpp_maybe Security update for grub2
SUSE-SLE-Module-Server-Applications-15-SP2-2021-683


This update for grub2 fixes the following issues: grub2 implements the new "SBAT" method for SHIM based secure boot revocation. (bsc#1182057) - CVE-2020-25632: Fixed a use-after-free in rmmod command (bsc#1176711) - CVE-2020-25647: Fixed an out-of-bound write in grub_usb_device_initialize() (bsc#1177883) - CVE-2020-27749: Fixed a stack buffer overflow in grub_parser_split_cmdline (bsc#1179264) - CVE-2020-27779, CVE-2020-14372: Disallow cutmem and acpi commands in secure boot mode (bsc#1179265 bsc#1175970) - CVE-2021-20225: Fixed a heap out-of-bounds write in short form option parser (bsc#1182262) - CVE-2021-20233: Fixed a heap out-of-bound write due to mis-calculation of space required for quoting (bsc#1182263)


cloud_download Downloads

Server Applications Module 15.2 x86_64
  • Packages
    grub2
    Bootloader with support for Linux, Multiboot and more
    2.04-9.34.1 lock src
    grub2-x86_64-xen
    Bootloader with support for Linux, Multiboot and more
    2.04-9.34.1 lock rpm