SUSE-SU-2022:2035-1 -- SLES grub2ID: oval:org.secpod.oval:def:89047785 | Date: (C)2022-10-28 (M)2024-05-09 |
Class: PATCH | Family: unix |
This update for grub2 fixes the following issues: This update provides security fixes and hardenings for Boothole 3 / Boothole 2022 - CVE-2021-3695: Fixed that a crafted PNG grayscale image could lead to out-of-bounds write in heap - CVE-2021-3696: Fixed that a crafted PNG image could lead to out-of-bound write during huffman table handling - CVE-2021-3697: Fixed that a crafted JPEG image could lead to buffer underflow write in the heap - CVE-2022-28733: Fixed fragmentation math in net/ip - CVE-2022-28734: Fixed an out-of-bound write for split http headers - CVE-2022-28735: Fixed some verifier framework changes - CVE-2022-28736: Fixed a use-after-free in chainloader command - Update SBAT security contact - Bump grub"s SBAT generation to 2 - Use boot disks in OpenFirmware, fixing regression caused when the root LV is completely in the boot LUN
Platform: |
SUSE Linux Enterprise Desktop 15 SP4 |
SUSE Linux Enterprise Server 15 SP4 |