-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 02 Oct 2023 16:11:34 +0200 Source: grub2 Binary: grub-common grub-common-dbgsym grub-ieee1275 grub-ieee1275-bin grub-ieee1275-bin-dbgsym grub-ieee1275-dbg grub-mount-udeb grub-theme-starfield grub2 grub2-common grub2-common-dbgsym Architecture: ppc64el Version: 2.06-3~deb11u6 Distribution: bullseye-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Julian Andres Klode Description: grub-common - GRand Unified Bootloader (common files) grub-ieee1275 - GRand Unified Bootloader, version 2 (Open Firmware version) grub-ieee1275-bin - GRand Unified Bootloader, version 2 (Open Firmware modules) grub-ieee1275-dbg - GRand Unified Bootloader, version 2 (Open Firmware debug files) grub-mount-udeb - export GRUB filesystems using FUSE (udeb) grub-theme-starfield - GRand Unified Bootloader, version 2 (starfield theme) grub2 - GRand Unified Bootloader, version 2 (dummy package) grub2-common - GRand Unified Bootloader (common files for version 2) Changes: grub2 (2.06-3~deb11u6) bullseye-security; urgency=medium . [ Mate Kukri ] * SECURITY UPDATE: Crafted file system images can cause out-of-bounds write and may leak sensitive information into the GRUB pager. - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-parsing-a-volume- label.patch: fs/ntfs: Fix an OOB read when parsing a volume label - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-parsing-bs-for- index-at.patch: fs/ntfs: Fix an OOB read when parsing bitmaps for index attributes - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-parsing-dory- entries-fr.patch: fs/ntfs: Fix an OOB read when parsing directory entries from resident and non-resident index attributes - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-reading-data-fhe- reside.patch: fs/ntfs: Fix an OOB read when reading data from the resident $DATA + attribute - CVE-2023-4693 * SECURITY UPDATE: Crafted file system images can cause heap-based buffer overflow and may allow arbitrary code execution and secure boot bypass. - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-write-when-parsing-the- ATTRIBUTE_LIST-.patch: fs/ntfs: Fix an OOB write when parsing the $ATTRIBUTE_LIST attribute for the $MFT file - d/patches/ntfs-cve-fixes/fs-ntfs-Make-code-more-readable.patch fs/ntfs: Make code more readable - CVE-2023-4692 . [ Julian Andres Klode ] * Bump SBAT to grub,4 Checksums-Sha1: 898d4bfa1b869bcd6875c251c4eb060f2ae76f77 10681792 grub-common-dbgsym_2.06-3~deb11u6_ppc64el.deb fb4c2104c623a12722779c6980a27baec5987f7d 2917504 grub-common_2.06-3~deb11u6_ppc64el.deb 852802a1fa978efad84bf5d2f22fd8dc5f1205d2 6272 grub-ieee1275-bin-dbgsym_2.06-3~deb11u6_ppc64el.deb 7251ef9cbe182565fdbcf881d1a1919e3ecf3009 816772 grub-ieee1275-bin_2.06-3~deb11u6_ppc64el.deb f2fbc0afffbf9a37408aec17b78519046dbf53eb 2636928 grub-ieee1275-dbg_2.06-3~deb11u6_ppc64el.deb 5d602591ce64aecc1b897db2bcea3b13eb328b1d 280000 grub-ieee1275_2.06-3~deb11u6_ppc64el.deb 02e6d3f906ec5876226b0d624fbc2febcc7e5be1 463648 grub-mount-udeb_2.06-3~deb11u6_ppc64el.udeb 6fd7f340d887c6b56adc53148dcd32f390565426 2394824 grub-theme-starfield_2.06-3~deb11u6_ppc64el.deb 502b53d53274399ae6857b2553ae7eb9a660726a 1507232 grub2-common-dbgsym_2.06-3~deb11u6_ppc64el.deb 0f80bb2241cc747114923fbcc8ca3fc1d36776ff 891036 grub2-common_2.06-3~deb11u6_ppc64el.deb e6eeaab345510532da6ab5f03f29201f1a1be688 13918 grub2_2.06-3~deb11u6_ppc64el-buildd.buildinfo ecc212d306240e1a5a85597d3739a07c39b7ddfa 242124 grub2_2.06-3~deb11u6_ppc64el.deb Checksums-Sha256: 2eecf46d554d6e86ea0797c130650bea22cfc60fb8f8d8ed52bc7f0eda41ce62 10681792 grub-common-dbgsym_2.06-3~deb11u6_ppc64el.deb 9a23b79f0f26439c887fa4ae51909cff9f5dd58316632a42567fe6ef2064d957 2917504 grub-common_2.06-3~deb11u6_ppc64el.deb 89b2b020b09340d78b1dc760835c7f516dd8581046461e36d3d4d2808751ae8c 6272 grub-ieee1275-bin-dbgsym_2.06-3~deb11u6_ppc64el.deb bf4a5a75270c0801c9195ae6ab0b5db2bac54693b11746e413192dc4c55f6316 816772 grub-ieee1275-bin_2.06-3~deb11u6_ppc64el.deb 67d87618595f40ffbff708eab9f340a2a23bf39d80bb502fc7fab669d4f34142 2636928 grub-ieee1275-dbg_2.06-3~deb11u6_ppc64el.deb afd2b767678befc2820d2663d3657fe4a5db5d95de04dfe90d614419d8cff947 280000 grub-ieee1275_2.06-3~deb11u6_ppc64el.deb d1b16da8be04419976a635576f134fe7b297a980f34222a6a3483e6d17b147e1 463648 grub-mount-udeb_2.06-3~deb11u6_ppc64el.udeb e5ef1344650ad38d32a53916ef1ce5a78907b31c532a5ab394f4fa55392723ad 2394824 grub-theme-starfield_2.06-3~deb11u6_ppc64el.deb f0c9c888099087a048a7719c009d03f77bac3f42a405077d55fb8c27ee308fb4 1507232 grub2-common-dbgsym_2.06-3~deb11u6_ppc64el.deb 55dedd68ebc3e73788a8eab740315e7c0389847ba3a7d9efc9ce30f5d57e4c00 891036 grub2-common_2.06-3~deb11u6_ppc64el.deb 66a4d852af890d8ccdbfebce92c8782de55d5ae56384b090d5283dea7411bc8f 13918 grub2_2.06-3~deb11u6_ppc64el-buildd.buildinfo eff64e782d23cfdc95cedf44a1e0200a55db6a29614f212a8028b3fb1f67a3dc 242124 grub2_2.06-3~deb11u6_ppc64el.deb Files: 6ca9dccd1a53a88fa10dc70e21b5ef74 10681792 debug optional grub-common-dbgsym_2.06-3~deb11u6_ppc64el.deb a7f3ff59b8f1d9454312c5b9963ae98c 2917504 admin optional grub-common_2.06-3~deb11u6_ppc64el.deb 86ab0ec38aa559123bf4d0e7beb66dbf 6272 debug optional grub-ieee1275-bin-dbgsym_2.06-3~deb11u6_ppc64el.deb f404b0da45b89953c0112cbde78ed581 816772 admin optional grub-ieee1275-bin_2.06-3~deb11u6_ppc64el.deb a132c04c8d7d093167004e1c9c7ba44d 2636928 debug optional grub-ieee1275-dbg_2.06-3~deb11u6_ppc64el.deb 24d0fe2ffd5d65667b9d2ac2f865f9cd 280000 admin optional grub-ieee1275_2.06-3~deb11u6_ppc64el.deb 8be8ae86564e66323fce305d36a608f5 463648 debian-installer optional grub-mount-udeb_2.06-3~deb11u6_ppc64el.udeb 98222402f350caa8c75ea74dc1d2926b 2394824 admin optional grub-theme-starfield_2.06-3~deb11u6_ppc64el.deb 5adb3ac2e11e8cfd8c8c29521a05e313 1507232 debug optional grub2-common-dbgsym_2.06-3~deb11u6_ppc64el.deb 1bb4e1301fea40fe45211a6ad21db732 891036 admin optional grub2-common_2.06-3~deb11u6_ppc64el.deb 6310413311b3373d34259fcdddac221c 13918 admin optional grub2_2.06-3~deb11u6_ppc64el-buildd.buildinfo 2a7544cd1d9d63114bec5f3f9f8364bd 242124 oldlibs optional grub2_2.06-3~deb11u6_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHDNCkvGgp2XShfnByW8ECaj2byoFAmUcUf4ACgkQyW8ECaj2 byrudhAArMRwI7iQ1ylloP4IUu2mmEW86lmT7A0rDNJDhCmb8DGdY8573qF3S72F ExUNcOxiS8zprQRB+6eOag2M1R3y+r+1dc03HO85Su1V+gblJ8s5HyyMRxTQcekp OS/XdtQUGwjOKfiNJoE05tNNVDR9kuzOV2ywgYvx/rbp2+G/XhtOjT4e7ags+B+E tybL7Fd340yyOr+ZeNwSrbR+ICb+xQxUySaws9RrwKndmiJ05gurAgom/sp/ZRhJ Z7TzGyLdPfa2eRnKYvIR6nhBUEEDVn/fhz0k61n3Ijqm/7lwokVYnlRPRoWHkVwH wJDcP8eJ6+ioU1EWp2jd+/9IBk3lzb3CSiqokJQnow8Lp2YCbogz4bvNK9W5cI8o UtoTLXdZr6UJcBDGv5VP/gICO4TkayDdU/DuxplRdzMGMXoasDpnf4PQbBQTvn4R qoXuEUV04Gxdq9SbdW+bS8VtrypqhT2PfclAIQrGzjH1C+kqmynudexUU1JEIkf7 N1f5hAVNPS/zmVn94lEfH8ck8O2cgekhqtOmyDRhMKRGVARYNjEVLFrV41sj2U3q vQZSO0uea5R6IQArmoVlc1bWtfM10pZ2euoxWQeZpEQkEEcD0iq3GfzH13W9BvT4 cf4dzflw3RqXuVK5hwyzJH+mPxwhuOZYOJ7nylZoshY7RKdMUB4= =VVJr -----END PGP SIGNATURE-----