[CLSA-2022:1669388927] grub2: Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2022-11-25
Description:
- CVE-2021-3981: Fix default privileges of grub.cfg file - CVE-2022-28736: Fix use-after-free bug when grub_cmd_chainloader is executed more than once before a boot attempt is performed. - CVE-2021-3695: Drop greyscale support to fix heap out-of-bounds write - CVE-2021-3696: Fix out of range insertion into huffman table - CVE-2021-3697: Fix integer undeflow which resulted in wild pointer write - CVE-2022-28733: Fix integer underflow which resulted in subsequent unpleasantness - CVE-2022-28734: Fix erros in handling of split http headers
Updated packages:
  • grub2-common-2.02-106.el8.tuxcare.els2.noarch.rpm
    sha:77efc4b8594ca1468f2bbccf587cf7fe6f18a6c7
  • grub2-efi-ia32-2.02-106.el8.tuxcare.els2.x86_64.rpm
    sha:6913b0bce8ef45c582f0b1851e1f80a7d2ddfc6a
  • grub2-efi-ia32-cdboot-2.02-106.el8.tuxcare.els2.x86_64.rpm
    sha:d4969efa3eb482c2346719736258c1bb5142a839
  • grub2-efi-ia32-modules-2.02-106.el8.tuxcare.els2.noarch.rpm
    sha:5f45f567093ab0219ee647fedd865ce8a11210e2
  • grub2-efi-x64-2.02-106.el8.tuxcare.els2.x86_64.rpm
    sha:f986fab11c1d7f801f1776513ceab3ad290fce02
  • grub2-efi-x64-cdboot-2.02-106.el8.tuxcare.els2.x86_64.rpm
    sha:079b35ed4f06564c068064f890b853a02c07e107
  • grub2-efi-x64-modules-2.02-106.el8.tuxcare.els2.noarch.rpm
    sha:43553cd472146fdf2af541a7182d129c80b8428e
  • grub2-pc-2.02-106.el8.tuxcare.els2.x86_64.rpm
    sha:c780e5c63ef6454e50238d277a334efcc3f6637e
  • grub2-pc-modules-2.02-106.el8.tuxcare.els2.noarch.rpm
    sha:0d0b8ee23a3b43236eb6ec0606a15eed059d5938
  • grub2-tools-2.02-106.el8.tuxcare.els2.x86_64.rpm
    sha:6bc6eb384aa52709add796228d38a71dca4d8e3f
  • grub2-tools-efi-2.02-106.el8.tuxcare.els2.x86_64.rpm
    sha:1707fa31e3cfb7b813d2db7495bc1615b622e24d
  • grub2-tools-extra-2.02-106.el8.tuxcare.els2.x86_64.rpm
    sha:9b193d596051ee07c9732ccb6a6d0a2d4e093445
  • grub2-tools-minimal-2.02-106.el8.tuxcare.els2.x86_64.rpm
    sha:68f8bf0937d7adf4bc26f19a2f8bf1d17ee63c06
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.