ELA-763-1 grub2 security update

integer overflows

2023-01-09
Packagegrub2
Version2.02~beta2-22+deb8u2 (jessie)


Several issues were found in GRUB2’s font handling code, which could result in crashes and potentially execution of arbitrary code. Further issues were found in image loading that could potentially lead to memory overflows. Please note that some integer overflow mitigations could not be applied because of builtin GCC functions which are only available in newer Debian versions. Only system administrators should be able to change grub2 fonts. If you use the default fonts, your system is not affected.



For Debian 8 jessie, these problems have been fixed in version 2.02~beta2-22+deb8u2.

We recommend that you upgrade your grub2 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.