Bugs fixes in "grub2-unsigned"
| Origin | Bug number | Title | Date fixed |
|---|---|---|---|
| Launchpad | 2073634 | [SRU] Enable suppression of /EndEntire message | 2025-01-14 |
| Launchpad | 2076651 | [SRU] Crash on RISC-V in virtual machine using KVM | 2025-01-14 |
| Launchpad | 2073634 | [SRU] Enable suppression of /EndEntire message | 2024-12-13 |
| Launchpad | 2076651 | [SRU] Crash on RISC-V in virtual machine using KVM | 2024-12-13 |
| CVE | CVE-2023-4692 | Crafted file system images can cause heap-based buffer overflow and may allow arbitrary code execution and secure boot bypass | 2023-10-04 |
| CVE | CVE-2023-4693 | Crafted file system images can cause out-of-bounds write and may leak sensitive information into the GRUB pager | 2023-10-04 |
| Launchpad | 2028931 | device tree protocol not always applied | 2023-10-04 |
| CVE | CVE-2023-4692 | Crafted file system images can cause heap-based buffer overflow and may allow arbitrary code execution and secure boot bypass | 2023-10-04 |
| CVE | CVE-2023-4693 | Crafted file system images can cause out-of-bounds write and may leak sensitive information into the GRUB pager | 2023-10-04 |
| Launchpad | 2028931 | device tree protocol not always applied | 2023-10-04 |
| CVE | CVE-2022-3775 | When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bi | 2023-01-30 |
| CVE | CVE-2022-2601 | A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size | 2023-01-30 |
| Launchpad | 1997006 | grub TDX enablement | 2023-01-30 |
| CVE | CVE-2022-3775 | When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bi | 2023-01-12 |
| CVE | CVE-2022-2601 | A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size | 2023-01-12 |
| Launchpad | 1997006 | grub TDX enablement | 2023-01-12 |
| CVE | CVE-2021-3697 | A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to | 2022-11-30 |
| CVE | CVE-2021-3696 | A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Co | 2022-11-30 |
| CVE | CVE-2021-3695 | A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data co | 2022-11-30 |
| Launchpad | 1930742 | cloud images in xenial do not get their boot path updated because we don't call grub-install --force-extra-removable | 2022-11-30 |
About
-
Send Feedback to @ubuntu_updates