Oval Definition:oval:org.opensuse.security:def:519
Revision Date:2022-06-10Version:1
Title:Security update for grub2 (Important)
Description:

This update for grub2 fixes the following issues:

This update provides security fixes and hardenings for Boothole 3 / Boothole 2022 (bsc#1198581)

- CVE-2021-3695: Fixed that a crafted PNG grayscale image could lead to out-of-bounds write in heap (bsc#1191184) - CVE-2021-3696: Fixed that a crafted PNG image could lead to out-of-bound write during huffman table handling (bsc#1191185) - CVE-2021-3697: Fixed that a crafted JPEG image could lead to buffer underflow write in the heap (bsc#1191186) - CVE-2022-28733: Fixed fragmentation math in net/ip (bsc#1198460) - CVE-2022-28734: Fixed an out-of-bound write for split http headers (bsc#1198493) - CVE-2022-28735: Fixed some verifier framework changes (bsc#1198495) - CVE-2022-28736: Fixed a use-after-free in chainloader command (bsc#1198496) - Update SBAT security contact (bsc#1193282) - Bump grub's SBAT generation to 2

- Use boot disks in OpenFirmware, fixing regression caused when the root LV is completely in the boot LUN (bsc#1197948)
Family:unixClass:patch
Status:Reference(s):1191184
1191185
1191186
1193282
1197948
1198460
1198493
1198495
1198496
1198581
CVE-2014-0467
CVE-2014-0467
CVE-2014-9116
CVE-2014-9116
CVE-2018-14349
CVE-2018-14349
CVE-2018-14350
CVE-2018-14350
CVE-2018-14351
CVE-2018-14351
CVE-2018-14352
CVE-2018-14352
CVE-2018-14353
CVE-2018-14353
CVE-2018-14354
CVE-2018-14354
CVE-2018-14355
CVE-2018-14355
CVE-2018-14356
CVE-2018-14356
CVE-2018-14357
CVE-2018-14357
CVE-2018-14358
CVE-2018-14358
CVE-2018-14359
CVE-2018-14359
CVE-2018-14360
CVE-2018-14360
CVE-2018-14361
CVE-2018-14361
CVE-2018-14362
CVE-2018-14362
CVE-2018-14363
CVE-2018-14363
CVE-2021-3695
CVE-2021-3696
CVE-2021-3697
CVE-2022-28733
CVE-2022-28734
CVE-2022-28735
CVE-2022-28736
SUSE-SU-2022:2035-1
Platform(s):openSUSE 13.1
openSUSE Leap 15.4
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 15 SP1
SUSE Linux Enterprise for SAP 12
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Live Patching 12
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Module for Containers 12
SUSE Linux Enterprise Module for Desktop Applications 15
SUSE Linux Enterprise Module for Legacy Software 12
SUSE Linux Enterprise Module for Public Cloud 12
SUSE Linux Enterprise Module for Toolchain 12
SUSE Linux Enterprise Module for Web Scripting 12
SUSE Linux Enterprise Module for Web Scripting 15
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • openSUSE Leap 15.4 is installed
  • AND Package Information
  • grub2-2.06-150400.11.5.2 is installed
  • OR grub2-arm64-efi-2.06-150400.11.5.2 is installed
  • OR grub2-arm64-efi-debug-2.06-150400.11.5.2 is installed
  • OR grub2-branding-upstream-2.06-150400.11.5.2 is installed
  • OR grub2-i386-pc-2.06-150400.11.5.2 is installed
  • OR grub2-i386-pc-debug-2.06-150400.11.5.2 is installed
  • OR grub2-powerpc-ieee1275-2.06-150400.11.5.2 is installed
  • OR grub2-powerpc-ieee1275-debug-2.06-150400.11.5.2 is installed
  • OR grub2-s390x-emu-2.06-150400.11.5.2 is installed
  • OR grub2-s390x-emu-debug-2.06-150400.11.5.2 is installed
  • OR grub2-snapper-plugin-2.06-150400.11.5.2 is installed
  • OR grub2-systemd-sleep-plugin-2.06-150400.11.5.2 is installed
  • OR grub2-x86_64-efi-2.06-150400.11.5.2 is installed
  • OR grub2-x86_64-efi-debug-2.06-150400.11.5.2 is installed
  • OR grub2-x86_64-xen-2.06-150400.11.5.2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND Package Information
  • avahi-0.6.32-30 is installed
  • OR avahi-lang-0.6.32-30 is installed
  • OR libavahi-client3-0.6.32-30 is installed
  • OR libavahi-client3-32bit-0.6.32-30 is installed
  • OR libavahi-common3-0.6.32-30 is installed
  • OR libavahi-common3-32bit-0.6.32-30 is installed
  • OR libavahi-core7-0.6.32-30 is installed
  • OR libdns_sd-0.6.32-30 is installed
  • OR libdns_sd-32bit-0.6.32-30 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • mutt-1.10.1-3.3.4 is installed
  • OR mutt-doc-1.10.1-3.3.4 is installed
  • OR mutt-lang-1.10.1-3.3.4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • mutt-1.10.1-3.3 is installed
  • OR mutt-doc-1.10.1-3.3 is installed
  • OR mutt-lang-1.10.1-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 is installed
  • AND Package Information
  • typelib-1_0-JavaScriptCore-4_0-2.24.1-3.24 is installed
  • OR typelib-1_0-WebKit2-4_0-2.24.1-3.24 is installed
  • OR typelib-1_0-WebKit2WebExtension-4_0-2.24.1-3.24 is installed
  • OR webkit2gtk3-2.24.1-3.24 is installed
  • OR webkit2gtk3-devel-2.24.1-3.24 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Web Scripting 15 is installed
  • AND jakarta-taglibs-standard-1.1.1-2 is installed
  • BACK