On Tue, Aug 11, 2026 at 12:26 PM Steve McIntyre <[email protected]> wrote:
>
> Adding the GRUB upstream development list on this too; the information
> is already public in the Debian BTS so there's no point trying to keep
> thie embargoed.
>
> On Tue, Aug 11, 2026 at 10:20:10AM +0200, Bastien Roucaries wrote:
> >Le mardi 11 août 2026, 06:19:06 heure d’été d’Europe centrale Carlos 
> >Henrique Lima Melara a écrit :
> >> Control: found -1 2.14~git20250718.0e36779-1
> >>
> >> Hi,
> >>
> >> On Mon, Aug 10, 2026 at 09:50:59PM +0200, Bastien Roucaries wrote:
> >> >
> >> > CVE-2025-13151 (libtasn1 - off-by-one in asn1_expand_octet_string, fixed 
> >> > in
> >> > 4.20.0)
> >> >
> >> > The fix changes:
> >> >   char name[2 * ASN1_MAX_NAME_SIZE + 1]
> >> >
> >> >  to:
> >> >    char name[2 * ASN1_MAX_NAME_SIZE + 2]
> >> >
> >> > This applies to two functions: asn1_expand_any_defined_by and
> >> > asn1_expand_octet_string.
> >> >
> >> > Grub2 vendor libtasn1 internally and show a partial fix -
> >> > asn1_expand_any_defined_by has been updated (+ 2 present) but
> >> > asn1_expand_octet_string still carries the vulnerable version (+ 1):
> >> >    - grub2 (grub-core/lib/libtasn1/lib/decoding.c)
> >> >         asn1_expand_any_defined_by: patched
> >> >      asn1_expand_octet_string: VULNERABLE
> >> >      Note: grub2 carries two separate embedded copies (libtasn1 and
> >> >  libtasn1-grub)
> >> >
> >> > Thanks to Gajendra Nath Soren
> >>
> >> This embedded copy was added in 9a26abbc368 (grub-2.14-rc1), so it only
> >> (possibly) affects forky/sid.
> >
> >Can we report upstream ?
> >
> >rouca
> >>
> >> Cheers,
> >> Charles
> >>
> >

Thanks for the heads-up. I created a task on the new GRUB issue tracker.

https://gitlab.freedesktop.org/gnu-grub/grub/-/work_items/66

Reply via email to