From 4c466f4d082dba9c6c82b370699194bb99c93843 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sat, 25 Nov 2023 11:18:39 +0000 Subject: [ GLSA 202311-14 ] GRUB: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/881413 Bug: https://bugs.gentoo.org/915187 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202311-14.xml | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 glsa-202311-14.xml diff --git a/glsa-202311-14.xml b/glsa-202311-14.xml new file mode 100644 index 000000000000..8ae2ab551c6b --- /dev/null +++ b/glsa-202311-14.xml @@ -0,0 +1,46 @@ + + + + GRUB: Multiple Vulnerabilities + Multiple vulnerabilities have been discoverd in GRUB, which may lead to secure boot circumvention or code execution. + grub + 2023-11-25 + 2023-11-25 + 881413 + 915187 + remote + + + 2.06-r9 + 2.06-r9 + + + +

GNU GRUB is a multiboot boot loader used by most Linux systems.

+
+ +

Multiple vulnerabilities have been discovered in GRUB. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All GRUB users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-boot/grub-2.06-r9" + +
+ + CVE-2022-2601 + CVE-2022-3775 + CVE-2023-4692 + CVE-2023-4693 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad