Bug 55434 - grub2: Multiple issues (5.0)
grub2: Multiple issues (5.0)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 5.0
All Linux
: P3 normal (vote)
: UCS 5.0-2-errata
Assigned To: Quality Assurance
Philipp Hahn
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-11-17 11:44 CET by Quality Assurance
Modified: 2022-11-23 16:08 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 6.4 (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2022-11-17 11:44:46 CET
New Debian grub2 2.06-3~deb10u2 fixes:
This update addresses the following issues:
2.06-3~deb10u2 (Sun, 13 Nov 2022 21:07:01 +0000)
[ Steve McIntyre ]
* Pull in upstream patches to harden font and image handling - CVE-2022-2601,  CVE-2022-3775.
* Bump SBAT level to 3 for grub-efi packages.
Comment 1 Quality Assurance univentionstaff 2022-11-17 12:00:10 CET
--- mirror/ftp/pool/main/g/grub2/grub2_2.06-3~deb10u1.dsc
+++ apt/ucs_5.0-0-errata5.0-2/source/grub2_2.06-3~deb10u2.dsc
@@ -1,3 +1,10 @@
+2.06-3~deb10u2 [Sun, 13 Nov 2022 21:07:01 +0000] Steve McIntyre <93sam@debian.org>:
+
+  [ Steve McIntyre ]
+  * Pull in upstream patches to harden font and image handling -
+    CVE-2022-2601, CVE-2022-3775.
+  * Bump SBAT level to 3 for grub-efi packages.
+
 2.06-3~deb10u1 [Mon, 01 Aug 2022 20:26:34 +0100] Steve McIntyre <93sam@debian.org>:
 
   [ Steve McIntyre ]

<http://piuparts.knut.univention.de/5.0-2/#2838695408113454753>
Comment 2 Quality Assurance univentionstaff 2022-11-22 09:49:34 CET
--- mirror/ftp/pool/main/g/grub2/grub2_2.06-3~deb10u1.dsc
+++ apt/ucs_5.0-0-errata5.0-2/source/grub2_2.06-3~deb10u2.dsc
@@ -1,3 +1,10 @@
+2.06-3~deb10u2 [Sun, 13 Nov 2022 21:07:01 +0000] Steve McIntyre <93sam@debian.org>:
+
+  [ Steve McIntyre ]
+  * Pull in upstream patches to harden font and image handling -
+    CVE-2022-2601, CVE-2022-3775.
+  * Bump SBAT level to 3 for grub-efi packages.
+
 2.06-3~deb10u1 [Mon, 01 Aug 2022 20:26:34 +0100] Steve McIntyre <93sam@debian.org>:
 
   [ Steve McIntyre ]

<http://piuparts.knut.univention.de/5.0-2/#7613152655441834933>
Comment 3 Philipp Hahn univentionstaff 2022-11-22 10:54:21 CET
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts
OK: grep -aA2  SBAT /usr/lib/grub/x86_64-efi-signed/grubx64.efi.signed
OK: reboot
OK: mokutil --sb-state  # SecureBoot enabled

[5.0-2] 07772dfd4c Bug #55434: grub2 2.06-3~deb10u2
 doc/errata/staging/grub2.yaml | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

[5.0-2] 6cd345d882 Bug #55434: grub2 2.06-3~deb10u2
 doc/errata/staging/grub2.yaml | 17 +++++++++++++++++
 1 file changed, 17 insertions(+)

[5.0-2] 07687ff11e Bug #55434: grub-efi-amd64-signed 1+2.06+3~deb10u2
 doc/errata/staging/grub-efi-amd64-signed.yaml | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

FYI:
 # https://github.com/fwupd/fwupd/wiki/fwupd-flatpak
 apt install flatpak
 flatpak remote-add --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo
 flatpak install flathub org.freedesktop.fwupd
 flatpak run org.freedesktop.fwupd get-devices

FYI:
 # https://github.com/fwupd/fwupd/wiki/fwupd-snap
 apt install snapd
 snap install fwupd --classic  # Depends on GLIBC 2.34