gpp_maybe
Security update for grub2
SUSE-SLE-Module-Server-Applications-15-SP3-2022-2064
This update for grub2 fixes the following issues: Security fixes and hardenings for boothole 3 / boothole 2022 (bsc#1198581) - CVE-2021-3695: Fixed that a crafted PNG grayscale image could lead to out-of-bounds write in heap (bsc#1191184) - CVE-2021-3696: Fixed that a crafted PNG image could lead to out-of-bound write during huffman table handling (bsc#1191185) - CVE-2021-3697: Fixed that a crafted JPEG image could lead to buffer underflow write in the heap (bsc#1191186) - CVE-2022-28733: Fixed fragmentation math in net/ip (bsc#1198460) - CVE-2022-28734: Fixed an out-of-bound write for split http headers (bsc#1198493) - CVE-2022-28735: Fixed some verifier framework changes (bsc#1198495) - CVE-2022-28736: Fixed a use-after-free in chainloader command (bsc#1198496) - Update SBAT security contact (bsc#1193282) - Bump grub's SBAT generation to 2 - Use boot disks in OpenFirmware, fixing regression caused when the root LV is completely in the boot LUN (bsc#1197948)
-
Release DateJun 13 2022
-
ReferencesBugzilla: 1193282, 1191184, 1198496, 1198493, 1191186, 1191185, 1198460, 1198495, 1197948, 1198581
CVEs: CVE-2022-28736, CVE-2021-3697, CVE-2022-28734, CVE-2021-3695, CVE-2022-28735, CVE-2022-28733, CVE-2021-3696 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Server Applications Module 15.3 x86_64
-
Packagesgrub2
Bootloader with support for Linux, Multiboot and moregrub2-x86_64-xen2.04-150300.22.20.2 lock src
Bootloader with support for Linux, Multiboot and more2.04-150300.22.20.2 lock rpm