Hi, please review the news item below.

Title: GRUB security update
Author: Mike Gilbert <[email protected]>
Content-Type: text/plain
Posted: 2015-12-18
Revision: 1
News-Item-Format: 1.0
Display-If-Installed: >=sys-boot/grub-2

A security flaw in GRUB's username/password authentication code has been
discovered. A user with access to the system console may bypass the
username prompt by entering a sequence of backspaces. See CVE-2015-8370.

This vulnerability has been fixed in sys-boot/grub-2.02_beta2-r8. If you
rely on GRUB's username/password functionality to secure systems, please
upgrade immediately.

After upgrading, make sure run the grub2-install command with options
appropriate for your system. See the GRUB2 Quick Start guide [1] for
examples. Your system will be vulerable until this action is performed.

[1] https://wiki.gentoo.org/wiki/GRUB2_Quick_Start

Reply via email to