-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 02 Oct 2023 16:11:34 +0200 Source: grub2 Binary: grub-common grub-common-dbgsym grub-efi grub-efi-arm64 grub-efi-arm64-bin grub-efi-arm64-dbg grub-efi-arm64-signed-template grub-mount-udeb grub-theme-starfield grub2-common grub2-common-dbgsym Architecture: arm64 Version: 2.06-3~deb11u6 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-arm-01) Changed-By: Julian Andres Klode Description: grub-common - GRand Unified Bootloader (common files) grub-efi - GRand Unified Bootloader, version 2 (dummy package) grub-efi-arm64 - GRand Unified Bootloader, version 2 (ARM64 UEFI version) grub-efi-arm64-bin - GRand Unified Bootloader, version 2 (ARM64 UEFI modules) grub-efi-arm64-dbg - GRand Unified Bootloader, version 2 (ARM64 UEFI debug files) grub-efi-arm64-signed-template - GRand Unified Bootloader, version 2 (ARM64 UEFI signing template) grub-mount-udeb - export GRUB filesystems using FUSE (udeb) grub-theme-starfield - GRand Unified Bootloader, version 2 (starfield theme) grub2-common - GRand Unified Bootloader (common files for version 2) Changes: grub2 (2.06-3~deb11u6) bullseye-security; urgency=medium . [ Mate Kukri ] * SECURITY UPDATE: Crafted file system images can cause out-of-bounds write and may leak sensitive information into the GRUB pager. - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-parsing-a-volume- label.patch: fs/ntfs: Fix an OOB read when parsing a volume label - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-parsing-bs-for- index-at.patch: fs/ntfs: Fix an OOB read when parsing bitmaps for index attributes - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-parsing-dory- entries-fr.patch: fs/ntfs: Fix an OOB read when parsing directory entries from resident and non-resident index attributes - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-reading-data-fhe- reside.patch: fs/ntfs: Fix an OOB read when reading data from the resident $DATA + attribute - CVE-2023-4693 * SECURITY UPDATE: Crafted file system images can cause heap-based buffer overflow and may allow arbitrary code execution and secure boot bypass. - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-write-when-parsing-the- ATTRIBUTE_LIST-.patch: fs/ntfs: Fix an OOB write when parsing the $ATTRIBUTE_LIST attribute for the $MFT file - d/patches/ntfs-cve-fixes/fs-ntfs-Make-code-more-readable.patch fs/ntfs: Make code more readable - CVE-2023-4692 . [ Julian Andres Klode ] * Bump SBAT to grub,4 Checksums-Sha1: 4cb69736636aaad7013960922f3e3ef14f52b16d 10328184 grub-common-dbgsym_2.06-3~deb11u6_arm64.deb f46f2126c7dec0b7e9a015691c4586c36e0b9b2a 2751960 grub-common_2.06-3~deb11u6_arm64.deb f44919a8b302c84dce783ce65679bb1a5a681927 1402672 grub-efi-arm64-bin_2.06-3~deb11u6_arm64.deb 781826c64e3d0cfb60e5f4ebbb090541505678d0 2803108 grub-efi-arm64-dbg_2.06-3~deb11u6_arm64.deb 0355851c7fddeca339224cbc6292a5d8f8619140 243304 grub-efi-arm64-signed-template_2.06-3~deb11u6_arm64.deb fe94d0d9571bf2690f303a72ec7a1a66a229b1c2 40136 grub-efi-arm64_2.06-3~deb11u6_arm64.deb 40d69d81e4867aa9401e282d1108fd9af1352e28 2388 grub-efi_2.06-3~deb11u6_arm64.deb 75ac3c9d55865e912c19de74063b115de40ea9f4 406084 grub-mount-udeb_2.06-3~deb11u6_arm64.udeb b224a6d439d79417bb0fee984634a76186fe60c1 2155240 grub-theme-starfield_2.06-3~deb11u6_arm64.deb b056921c50c9a8ec7a084b6165c8bd4c53e98c42 1459608 grub2-common-dbgsym_2.06-3~deb11u6_arm64.deb 3b4aba7fe1c352e345514632dd6f5b3170488f0b 583264 grub2-common_2.06-3~deb11u6_arm64.deb 8cd32ce14fe7614202cac7fd7999f254b9dd5444 13946 grub2_2.06-3~deb11u6_arm64-buildd.buildinfo Checksums-Sha256: 871057a0f5643f448a024d2fd35565e59836e9110117938fa13dc32c4b7ca291 10328184 grub-common-dbgsym_2.06-3~deb11u6_arm64.deb 2d24c5dc708c06341dd56bf22653103f477c67e62ff13d5e81fbd36d15d44912 2751960 grub-common_2.06-3~deb11u6_arm64.deb ade2ac2b983a4726f9b19910126cb713702b4e7c36e0e944a52162841c0c7ee5 1402672 grub-efi-arm64-bin_2.06-3~deb11u6_arm64.deb 84634885a8f1de41dc6f7ffb40f4343b70f9edc615521e830eeb15ceb03a0a5d 2803108 grub-efi-arm64-dbg_2.06-3~deb11u6_arm64.deb b197b5322411daa0fbb0c743be0332b82bbc94267a23e9b4649e324a80e192bf 243304 grub-efi-arm64-signed-template_2.06-3~deb11u6_arm64.deb bc14a63579cdc1004d4a37e396a9dd7460b55a87a66e43768aaa845e300adda5 40136 grub-efi-arm64_2.06-3~deb11u6_arm64.deb eb6aee8a2d479675dedde8e12cc2938d8efc4da7300db6e6d375242d06284856 2388 grub-efi_2.06-3~deb11u6_arm64.deb a44d0805359b8cc8a1ffaac70e6c382a235c9a201b09a25bb1a6ba2f68e55ad0 406084 grub-mount-udeb_2.06-3~deb11u6_arm64.udeb 5e67cbe35ed33f2e82f8ae239787aa588177b1b07bae0a82fd4ef0573ab9c7b0 2155240 grub-theme-starfield_2.06-3~deb11u6_arm64.deb 373dfe4856c4ac8f84f45f3bddb41fdc6ffb91bc1d7de6b5c3a60a88b7d61a1c 1459608 grub2-common-dbgsym_2.06-3~deb11u6_arm64.deb a7cd58e830ff63e1e68b6b0ca6cb68acd0802870d65a3e899963c271eb72167f 583264 grub2-common_2.06-3~deb11u6_arm64.deb e0a6346f7be6b0ef5278dc2a84941ef185a9fa17df6e7a76e0c436bde98ceb70 13946 grub2_2.06-3~deb11u6_arm64-buildd.buildinfo Files: a58cdebf4eebf3f86729486df3aa76f7 10328184 debug optional grub-common-dbgsym_2.06-3~deb11u6_arm64.deb aa5602c821f574d6458de9c0b0014c07 2751960 admin optional grub-common_2.06-3~deb11u6_arm64.deb 10079d3218983cb552248cc201ed88fe 1402672 admin optional grub-efi-arm64-bin_2.06-3~deb11u6_arm64.deb 374f15bf1cb5761ce4fb0ce3b9dab01a 2803108 debug optional grub-efi-arm64-dbg_2.06-3~deb11u6_arm64.deb 446781297bb0a7653b460658b8a29c0f 243304 admin optional grub-efi-arm64-signed-template_2.06-3~deb11u6_arm64.deb bbc5310ec79dee351fd7798e9eb38820 40136 admin optional grub-efi-arm64_2.06-3~deb11u6_arm64.deb 0fe63ec762b5fd48e389362b237ed6e5 2388 admin optional grub-efi_2.06-3~deb11u6_arm64.deb b23525172685784255e38b10dbc2aab8 406084 debian-installer optional grub-mount-udeb_2.06-3~deb11u6_arm64.udeb bc574aa9838b8390d496efead69af7c6 2155240 admin optional grub-theme-starfield_2.06-3~deb11u6_arm64.deb f849c576b0bb7f4f33d87873190ef5be 1459608 debug optional grub2-common-dbgsym_2.06-3~deb11u6_arm64.deb 3568fb014d60d86d12c6909620d656a4 583264 admin optional grub2-common_2.06-3~deb11u6_arm64.deb efb6f369607c62fc4c536a1539829145 13946 admin optional grub2_2.06-3~deb11u6_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Prg5L5o4koxD5sKbi61NfD5HDwFAmUcjqsACgkQbi61NfD5 HDwzHw//XK0PZWaC92AfWlDQ24Ie7lGSZpje5UG5OUBIVmg6VfP/AgNhpgykgjMn zk4iMfGojXHBc95tQ2GuRoTj5vXiMaw29+sAJqBwwvZl2oOHtXtkZhsMjAiKr96i FciFW+3oQ7ZbuO+l71n7KZbQpYe4G71N1wD1gShxpBsnlKBibuxHylvziCbZJwtV gYqLSpz/ZVqjuzHe/O6RMnh53AK5gd01Y55PwDht7HncNyvj92pkdrJpg93DQZeh 1nu2hQnmDNh7B0WbUgvB8DNbaGGzg9F33CHGyXoS2GYUFMAcKrwJb4t68FrmlnnP sZKOzZot6XztMJjZ4t/EqKAiMDriQXUH1gJiMjJYRm/KCRqznlU88VinwmFNR85V h2pPcWfNsdEHC0mFXYsFb1SsWywhz+6sX6uKJ9zQp0B197291UqsDM6dGJll2Xq9 DcptyJX4CIz+wDmfsbOQoFWX0GvFPYvXwaNaD0a4uymriYLjOcaW9D0xhax+wH8S qgfxxQ0KLo/SuNZt8mZAWMVXJtqoYccuyUxUVpYVCrG1CXIjkbObcuZNckGmHtB6 surRkDYcMpYGZveu1eUFSZzZeIWuiMaYyFd6mCGfVCFVYnULGbZKx36oFFtEjKun DGEozWw7dxKgZRMuVqii9uqeHseFo5sUAVxGJFf8y6x4zPwZp8Q= =f2V6 -----END PGP SIGNATURE-----