Skip to content

Commit 00529b7

Browse files
committed
advisories: add BRSAs for grub v2.0.6-61
Signed-off-by: Jingwei Wang <jweiw@amazon.com>
1 parent e8151ba commit 00529b7

21 files changed

Lines changed: 357 additions & 0 deletions
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-0an6ctj2omby"
3+
title = "grub CVE-2024-45774"
4+
cve = "CVE-2024-45774"
5+
severity = "moderate"
6+
description = "The JPEG parser in GRUB2 is vulnerable to an out-of-bounds write when processing malformed JPEG data, enabling potential bypasses of secure boot protections."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-13T22:18:07Z
16+
arches = ["aarch64", "x86_64"]
17+
version = "staging"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-61eomplftwut"
3+
title = "grub CVE-2025-0689"
4+
cve = "CVE-2025-0689"
5+
severity = "moderate"
6+
description = "A flaw in the GRUB UDF module's grub_udf_read_block() function's handling of disk reads can lead to a heap-based buffer overflow, potentially resulting in arbitrary code execution."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-16T16:19:23Z
16+
arches = ["aarch64", "x86_64"]
17+
version = "staging"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-bqnwwaeuien9"
3+
title = "grub CVE-2025-0678"
4+
cve = "CVE-2025-0678"
5+
severity = "moderate"
6+
description = "A flaw in the GRUB squash4 module's direct_read() function's data reading logic allows an integer overflow that can lead to a heap-based out-of-bounds write, potentially resulting in arbitrary code execution."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-16T16:10:53Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "staging"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-gaoizxbk9pvv"
3+
title = "grub CVE-2025-0690"
4+
cve = "CVE-2025-0690"
5+
severity = "moderate"
6+
description = "A flaw in the GRUB read command's handling of input length can lead to an integer overflow, resulting in an out-of-bounds write that could corrupt critical data and potentially bypass secure boot."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-16T16:20:26Z
16+
arches = ["aarch64", "x86_64"]
17+
version = "staging"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-hipeh9xcy2vf"
3+
title = "grub CVE-2024-45777"
4+
cve = "CVE-2024-45777"
5+
severity = "moderate"
6+
description = "A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-13T23:23:11Z
16+
arches = ["aarch64", "x86_64"]
17+
version = "staging"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-ipa3kqsg9jqr"
3+
title = "grub CVE-2024-45776"
4+
cve = "CVE-2024-45776"
5+
severity = "moderate"
6+
description = "When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound reads and writes."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-13T23:25:21Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "staging"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-irdy4tw47kbe"
3+
title = "grub CVE-2024-45775"
4+
cve = "CVE-2024-45775"
5+
severity = "moderate"
6+
description = "A flaw in the grub_extcmd_dispatcher() function of GRUB2 could lead to a denial of service or potential data corruption due to a missing check for failed memory allocation."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-13T23:06:52Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "staging"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-kznre2fpo5dy"
3+
title = "grub CVE-2025-0684"
4+
cve = "CVE-2025-0684"
5+
severity = "moderate"
6+
description = "A flaw in the GRUB reiserfs module's grub_reiserfs_read_symlink() function's handling of symlinks allows an integer overflow that can lead to a heap-based out-of-bounds write during data reading, potentially resulting in arbitrary code execution."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-16T16:12:39Z
16+
arches = ["x86_64", "aarch64"]
17+
version = "staging"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-mkykhhjwi2va"
3+
title = "grub CVE-2025-0677"
4+
cve = "CVE-2025-0677"
5+
severity = "moderate"
6+
description = "A flaw in the grub_ufs_lookup_symlink() function's handling of symlinks could lead to a heap-based out-of-bounds write, potentially resulting in arbitrary code execution."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-16T16:06:51Z
16+
arches = ["aarch64", "x86_64"]
17+
version = "staging"
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-nxm6fy1g6kkd"
3+
title = "grub CVE-2025-0686"
4+
cve = "CVE-2025-0686"
5+
severity = "moderate"
6+
description = "A flaw in the GRUB romfs module's grub_romfs_read_symlink() function's handling of symlinks allows an integer overflow that can lead to a heap-based out-of-bounds write when calling grub_disk_read(), potentially resulting in arbitrary code execution."
7+
8+
[[advisory.products]]
9+
package-name = "grub"
10+
patched-version = "2.06"
11+
patched-epoch = "0"
12+
13+
[updateinfo]
14+
author = "jweiw"
15+
issue-date = 2025-06-16T16:18:16Z
16+
arches = ["aarch64", "x86_64"]
17+
version = "staging"

0 commit comments

Comments
 (0)