-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 02 Oct 2023 16:11:34 +0200 Source: grub2 Binary: grub-common grub-common-dbgsym grub-ieee1275 grub-ieee1275-bin grub-ieee1275-bin-dbgsym grub-ieee1275-dbg grub-mount-udeb grub-theme-starfield grub2 grub2-common grub2-common-dbgsym Architecture: ppc64el Version: 2.06-13+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Julian Andres Klode Description: grub-common - GRand Unified Bootloader (common files) grub-ieee1275 - GRand Unified Bootloader, version 2 (Open Firmware version) grub-ieee1275-bin - GRand Unified Bootloader, version 2 (Open Firmware modules) grub-ieee1275-dbg - GRand Unified Bootloader, version 2 (Open Firmware debug files) grub-mount-udeb - export GRUB filesystems using FUSE (udeb) grub-theme-starfield - GRand Unified Bootloader, version 2 (starfield theme) grub2 - GRand Unified Bootloader, version 2 (dummy package) grub2-common - GRand Unified Bootloader (common files for version 2) Changes: grub2 (2.06-13+deb12u1) bookworm-security; urgency=medium . [ Mate Kukri ] * SECURITY UPDATE: Crafted file system images can cause out-of-bounds write and may leak sensitive information into the GRUB pager. - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-parsing-a-volume- label.patch: fs/ntfs: Fix an OOB read when parsing a volume label - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-parsing-bs-for- index-at.patch: fs/ntfs: Fix an OOB read when parsing bitmaps for index attributes - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-parsing-dory- entries-fr.patch: fs/ntfs: Fix an OOB read when parsing directory entries from resident and non-resident index attributes - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-read-when-reading-data-fhe- reside.patch: fs/ntfs: Fix an OOB read when reading data from the resident $DATA + attribute - CVE-2023-4693 * SECURITY UPDATE: Crafted file system images can cause heap-based buffer overflow and may allow arbitrary code execution and secure boot bypass. - d/patches/ntfs-cve-fixes/fs-ntfs-Fix-an-OOB-write-when-parsing-the- ATTRIBUTE_LIST-.patch: fs/ntfs: Fix an OOB write when parsing the $ATTRIBUTE_LIST attribute for the $MFT file - d/patches/ntfs-cve-fixes/fs-ntfs-Make-code-more-readable.patch fs/ntfs: Make code more readable - CVE-2023-4692 . [ Julian Andres Klode ] * Bump SBAT to grub,4 Checksums-Sha1: 7a7e7d4dc056406490d94b7eab01e3ecbe689e7d 10541664 grub-common-dbgsym_2.06-13+deb12u1_ppc64el.deb e21d608b8b2c8b7ee22c2c4dc8a2041c4ba7d606 2852312 grub-common_2.06-13+deb12u1_ppc64el.deb 38340a219a7670d873748949a15fd443afd6b591 6264 grub-ieee1275-bin-dbgsym_2.06-13+deb12u1_ppc64el.deb 666a025ce00e1883de56f60529f1f47087766132 754228 grub-ieee1275-bin_2.06-13+deb12u1_ppc64el.deb a3b0053f3ccf560267bc60a03721c96463ff310a 2643580 grub-ieee1275-dbg_2.06-13+deb12u1_ppc64el.deb 5c335ddbdebd4dbc6e43d66fb35d6cd56f93104f 226244 grub-ieee1275_2.06-13+deb12u1_ppc64el.deb 2808a8fcd7a59b1f97aca416a7345459d27f79fb 460064 grub-mount-udeb_2.06-13+deb12u1_ppc64el.udeb 932eb9c4547a25a62d7bb17b6e4372e7108b7a27 2336296 grub-theme-starfield_2.06-13+deb12u1_ppc64el.deb 4c1ddd32d4cd61072a354a1b42fe707cf3bb0870 1475484 grub2-common-dbgsym_2.06-13+deb12u1_ppc64el.deb 4df66f6f4e04185efcca022e7fd7ecc8cf94223b 829072 grub2-common_2.06-13+deb12u1_ppc64el.deb 5c1d4c5a4419f80b8b5d3dd24a6452263925a80d 13408 grub2_2.06-13+deb12u1_ppc64el-buildd.buildinfo 61a3751e7c639f8d676c1c0d918f1ef8b4916dc6 182932 grub2_2.06-13+deb12u1_ppc64el.deb Checksums-Sha256: 0839928490fadecf51cce6c22fd5bd8fe4d40f901bcd1da0058451108c78672f 10541664 grub-common-dbgsym_2.06-13+deb12u1_ppc64el.deb c456449a0229bffefecb326093b72180e987eeec33f13c546def907ddd538f37 2852312 grub-common_2.06-13+deb12u1_ppc64el.deb 2b82a735b97aa04e0fd16223a88945ed2d8979dfeeb8684ce955576fc475ac46 6264 grub-ieee1275-bin-dbgsym_2.06-13+deb12u1_ppc64el.deb 3bdcbb93f83ad2383b5d856091d20b98cd85ea09e12403126602ef2f9cff4ff6 754228 grub-ieee1275-bin_2.06-13+deb12u1_ppc64el.deb 73d2d5452e06b08e60ef2a67fabc5bc97a0e7287be78e242391643ecaaeec9ce 2643580 grub-ieee1275-dbg_2.06-13+deb12u1_ppc64el.deb 61570edb63a8c4b7847624140a78ea94184e42c978a0a3a2a06605104ee7be69 226244 grub-ieee1275_2.06-13+deb12u1_ppc64el.deb 420d4c898d43cb56bd58a1b88e65054aea28b335f1010f35c57b4b6c2b276681 460064 grub-mount-udeb_2.06-13+deb12u1_ppc64el.udeb 37420f868432e5c61c898f2e2325aa675218058346f1977d7e2dbfbc4c0d84d8 2336296 grub-theme-starfield_2.06-13+deb12u1_ppc64el.deb 5a5c5db74916c57e165784fb1861c2f875143eb7155c392de3e8e40bb2c7aa7e 1475484 grub2-common-dbgsym_2.06-13+deb12u1_ppc64el.deb b3f747d714473db2cafb6b19c4f26ac63866d7c69796256d40c246bb0b4734ca 829072 grub2-common_2.06-13+deb12u1_ppc64el.deb 9a792606228439dd43635b292555df3d5c8e43e0a060ef696c5321683275d488 13408 grub2_2.06-13+deb12u1_ppc64el-buildd.buildinfo f1a4bae41abf2fc62ecc6f9f041fda394cdf4580e959a9e9176c2ad3e8099798 182932 grub2_2.06-13+deb12u1_ppc64el.deb Files: 79b249c396050044370ea623fc6e95e6 10541664 debug optional grub-common-dbgsym_2.06-13+deb12u1_ppc64el.deb e0a30ee25cc4678d58bc6b27bc4571d1 2852312 admin optional grub-common_2.06-13+deb12u1_ppc64el.deb a2b7b969bc1114f4cea9b97dda6de2c3 6264 debug optional grub-ieee1275-bin-dbgsym_2.06-13+deb12u1_ppc64el.deb dea6c7270f527cb3d97d66aac4ecd951 754228 admin optional grub-ieee1275-bin_2.06-13+deb12u1_ppc64el.deb 01591f16abfc8c72f699945ae96d25f2 2643580 debug optional grub-ieee1275-dbg_2.06-13+deb12u1_ppc64el.deb 9d3b1db79b41c761e1cf4775de11b923 226244 admin optional grub-ieee1275_2.06-13+deb12u1_ppc64el.deb 1c2cd0cf80129106ab1caf09b737eb3a 460064 debian-installer optional grub-mount-udeb_2.06-13+deb12u1_ppc64el.udeb a1f9ccd92783191a592f96fe7480567e 2336296 admin optional grub-theme-starfield_2.06-13+deb12u1_ppc64el.deb d5a1ad6b74651096b787b8514febe7f0 1475484 debug optional grub2-common-dbgsym_2.06-13+deb12u1_ppc64el.deb 1310f15af46a91498d7f44f0554b4f98 829072 admin optional grub2-common_2.06-13+deb12u1_ppc64el.deb 407c5422cd316ac2d3a6abae90587d47 13408 admin optional grub2_2.06-13+deb12u1_ppc64el-buildd.buildinfo d07cd390abcdeaa1c38828fb380c3b1e 182932 oldlibs optional grub2_2.06-13+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHDNCkvGgp2XShfnByW8ECaj2byoFAmUcUq8ACgkQyW8ECaj2 byoN4g//aTX/nHAxrKqp4a8Fln9neofozZVF/eYMsX0/i6gxt6Z9QOEDscuyfPSg tGRPjQDQhMwYOkmTd06SYRORuGutanD31Ii/phqIu4uKsO+wBYvJtIkr56cuh5Ih BWf/0QTEzmAV1SpTLSB6HcgD+EhshGImruOHlWQt34CknU2lOgMdW/geN42wYh4Z wkTwNqbL4HZZFquvnZ8JsOwfeTHQqeF2G7FdQuwA4lsNrnFE7ih4Gv4xz0raWr87 GhRx0mxryDqhDjGXRUdKiz0WLeoG1KnyPGEWo8BKIn3ud0G5DzZwKliBO6NyQPsL vBcKPZslLP6cVF97070/rgps6mBE3shUFpbyoJURJd+Vt3qhf4l4zOCfrt5z2vR9 gnr1EGB7Wi5ptFJs3ownt9cAy4mwjNiNJ5B0/y5onCSH5uWBGNhxJ3obvPauesa7 wSA1PahYa/cGgvjiy52ZOR1hvw7EC0/Dtqod8V9ypJCVA2pN6UDqhiQJCEN60K9Q JbEBbz12c2px1k2n2VoxJyowy/x8yEooZRLnvwlURrf9QJfFW7rbMyP+xmEDOJlU AZGyqfQlxHuZj8eC+LeN0ra5h+58+WtUNq8Ie/6GWnpE9udeJjiSx4E2nh8YCFEI JTFePE+q2qDPyrBIWiJC+5q6Lk9KRJ94BtpBdme3IRYCxxUNmqU= =mjgR -----END PGP SIGNATURE-----