grub2: backport GRUB2 security fixes for six CVEs #2
No reviewers
Labels
No labels
auto-analysis
cve
match-cpe-range
needs-triage
security
severity-high
source-niceos-scan
source-nvd
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
rpms/grub2!2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "cve-grub2-CVE-2024-45782-CVE-2024-56737-CVE-2025-0678"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Backport GRUB2 security fixes relevant to grub2 2.12-1 for the following CVEs:
Impact
These issues affect filesystem handlers and gettext module lifetime handling in GRUB2. Several of them can lead to heap corruption or use-after-free in the pre-boot environment, with potential secure-boot bypass impact.
Strategy
Use targeted backports into the existing 2.12 branch rather than a full major-version jump, unless downstream policy prefers a broader update path.
Validation