From 85261a4d217482e1c124937d57ec98a0aabaee59 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sun, 25 Sep 2022 17:34:04 +0100 Subject: gentoo auto-resync : 25:09:2022 - 17:34:03 --- metadata/glsa/glsa-202209-12.xml | 53 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 53 insertions(+) create mode 100644 metadata/glsa/glsa-202209-12.xml (limited to 'metadata/glsa/glsa-202209-12.xml') diff --git a/metadata/glsa/glsa-202209-12.xml b/metadata/glsa/glsa-202209-12.xml new file mode 100644 index 000000000000..f7b8e7ebc453 --- /dev/null +++ b/metadata/glsa/glsa-202209-12.xml @@ -0,0 +1,53 @@ + + + + GRUB: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in GRUB, the worst of which may allow for secureboot bypass. + grub + 2022-09-25 + 2022-09-25 + 850535 + 835082 + local + + + 2.06 + 2.06 + + + +

GNU GRUB is a multiboot boot loader used by most Linux systems.

+
+ +

Multiple vulnerabilities have been discovered in GRUB. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All GRUB users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-boot/grub-2.06-r3" + + +

After upgrading, make sure to run the grub-install command with options appropriate for your system. See the GRUB2 Gentoo Wiki page for directions. Your system will be vulnerable until this action is performed.

+
+ + CVE-2021-3695 + CVE-2021-3696 + CVE-2021-3697 + CVE-2021-3981 + CVE-2022-28733 + CVE-2022-28734 + CVE-2022-28735 + CVE-2022-28736 + CVE-2022-28737 + + ajak + ajak +
\ No newline at end of file -- cgit v1.2.3