Information on source package grub2

Available versions

ReleaseVersion
bullseye2.06-3~deb11u6
bookworm2.06-13+deb12u1
trixie2.12-5
sid2.12-5

Open issues

BugbullseyebookwormtrixiesidDescription
CVE-2025-1125vulnerablevulnerablevulnerablevulnerablefs/hfs: Interger overflow may lead to heap based out-of-bounds write
CVE-2025-1118vulnerablevulnerablevulnerablevulnerableA flaw was found in grub2. Grub's dump command is not blocked when gru ...
CVE-2025-0690vulnerablevulnerablevulnerablevulnerableread: Integer overflow may lead to out-of-bounds write
CVE-2025-0689vulnerablevulnerablevulnerablevulnerableudf: Heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution
CVE-2025-0686vulnerablevulnerablevulnerablevulnerableromfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data
CVE-2025-0685vulnerablevulnerablevulnerablevulnerablejfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data
CVE-2025-0684vulnerablevulnerablevulnerablevulnerablereiserfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data
CVE-2025-0678vulnerablevulnerablevulnerablevulnerablesquash4: Integer overflow may lead to heap based out-of-bounds write when reading data
CVE-2025-0677vulnerablevulnerablevulnerablevulnerableA flaw was found in grub2. When performing a symlink lookup, the grub' ...
CVE-2025-0624vulnerablevulnerablevulnerablevulnerableA flaw was found in grub2. During the network boot process, when tryin ...
CVE-2025-0622vulnerablevulnerablevulnerablevulnerableA flaw was found in command/gpg. In some scenarios, hooks created by l ...
CVE-2024-56738vulnerablevulnerable (no DSA)vulnerablevulnerableGNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorit ...
CVE-2024-56737vulnerablevulnerable (no DSA)vulnerablevulnerableGNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in ...
CVE-2024-49504vulnerablevulnerablevulnerablevulnerablegrub2 allowed attackers with access to the grub shell to access files ...
CVE-2024-45783vulnerablevulnerablevulnerablevulnerableA flaw was found in grub2. When failing to mount an HFS+ grub, the hfs ...
CVE-2024-45782vulnerablevulnerablevulnerablevulnerablefs/hfs: strcpy() using the volume name (fs/hfs.c:382)
CVE-2024-45781vulnerablevulnerablevulnerablevulnerableA flaw was found in grub2. When reading a symbolic link's name from a ...
CVE-2024-45780vulnerablevulnerablevulnerablevulnerablefs/tar: Integer Overflow causes Heap OOB Write
CVE-2024-45779vulnerablevulnerablevulnerablevulnerablefs/bfs: Integer overflow leads to Heap OOB Read (Write?) in the BFS parser
CVE-2024-45778vulnerablevulnerablevulnerablevulnerablefs/bfs: Integer overflow in the BFS parser
CVE-2024-45777vulnerablevulnerablevulnerablevulnerableA flaw was found in grub2. The calculation of the translation buffer w ...
CVE-2024-45776vulnerablevulnerablevulnerablevulnerableWhen reading the language .mo file in grub_mofile_open(), grub2 fails ...
CVE-2024-45775vulnerablevulnerablevulnerablevulnerableA flaw was found in grub2 where the grub_extcmd_dispatcher() function ...
CVE-2024-45774vulnerablevulnerablevulnerablevulnerableA flaw was found in grub2. A specially crafted JPEG file can cause the ...
CVE-2021-3981vulnerable (no DSA)fixedfixedfixedA flaw in grub2 was found where its configuration file, known as grub. ...

Resolved issues

BugDescription
CVE-2024-2312GRUB2 does not call the module fini functions on exit, leading to Debi ...
CVE-2024-1048A flaw was found in the grub2-set-bootflag utility of grub2. After the ...
CVE-2023-4693An out-of-bounds read flaw was found on grub2's NTFS filesystem driver ...
CVE-2023-4692An out-of-bounds write flaw was found in grub2's NTFS filesystem drive ...
CVE-2023-4001An authentication bypass flaw was found in GRUB due to the way that GR ...
CVE-2022-28736There's a use-after-free vulnerability in grub_cmd_chainloader() funct ...
CVE-2022-28735The GRUB2's shim_lock verifier allows non-kernel files to be loaded on ...
CVE-2022-28734Out-of-bounds write when handling split HTTP headers; When handling sp ...
CVE-2022-28733Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP ...
CVE-2022-3775When rendering certain unicode sequences, grub2's font code doesn't pr ...
CVE-2022-2601A buffer overflow was found in grub_font_construct_glyph(). A maliciou ...
CVE-2021-46705A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE ...
CVE-2021-20233A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() ...
CVE-2021-20225A flaw was found in grub2 in versions prior to 2.06. The option parser ...
CVE-2021-3697A crafted JPEG image may lead the JPEG reader to underflow its data po ...
CVE-2021-3696A heap out-of-bounds write may heppen during the handling of Huffman t ...
CVE-2021-3695A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write ...
CVE-2021-3418If certificates that signed grub are installed into db, grub can be bo ...
CVE-2020-27779A flaw was found in grub2 in versions prior to 2.06. The cutmem comman ...
CVE-2020-27749A flaw was found in grub2 in versions prior to 2.06. Variable names pr ...
CVE-2020-25647A flaw was found in grub2 in versions prior to 2.06. During USB device ...
CVE-2020-25632A flaw was found in grub2 in versions prior to 2.06. The rmmod impleme ...
CVE-2020-15707Integer overflows were discovered in the functions grub_cmd_initrd and ...
CVE-2020-15706GRUB2 contains a race condition in grub_script_function_create() leadi ...
CVE-2020-15705GRUB2 fails to validate kernel signature when booted directly without ...
CVE-2020-14372A flaw was found in grub2 in versions prior to 2.06, where it incorrec ...
CVE-2020-14311There is an issue with grub2 before version 2.06 while handling symlin ...
CVE-2020-14310There is an issue on grub2 before version 2.06 at function read_sectio ...
CVE-2020-14309There's an issue with grub2 in all versions before 2.06 when handling ...
CVE-2020-14308In grub2 versions before 2.06 the grub memory allocator doesn't check ...
CVE-2020-10713A flaw was found in grub2, prior to version 2.06. An attacker may use ...
CVE-2019-14865A flaw was found in the grub2-set-bootflag utility of grub2. A local a ...
CVE-2017-9763The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013 ...
CVE-2015-8370Multiple integer underflows in Grub2 1.98 through 2.02 allow physicall ...
CVE-2015-5281The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) ...
CVE-2013-4577A certain Debian patch for GNU GRUB uses world-readable permissions fo ...
CVE-2009-4128GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted ...

Security announcements

DSA / DLADescription
DSA-5519-1grub2 - security update
DLA-3605-1grub2 - security update
DLA-3190-2grub2 - security update
DLA-3190-1grub2 - security update
DSA-5280-1grub2 - security update
DSA-4867-1grub2 - security update
DSA-4735-2grub2 - regression update
DSA-4735-1grub2 - security update
DSA-3421-1grub2 - security update
DLA-368-1grub2 - security update

Search for package or bug name: Reporting problems