Bug#1132510: marked as done (bookworm-pu: package grub2/2.06-13+deb12u2)
Your message dated Sat, 16 May 2026 11:07:42 + with message-id and subject line Released with 12.14 has caused the Debian Bug report #1132510, regarding bookworm-pu: package grub2/2.06-13+deb12u2 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 1132510: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132510 Debian Bug Tracking System Contact [email protected] with problems --- Begin Message --- Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: [email protected] Control: affects -1 + src:grub2 User: [email protected] Usertags: pu Hi! Along with the update to shim in bookworm, I'd like to update our grub2 packages. The key changes here are: * Backport lots of CVE fixes from the GRUB updates in 2025 * Disable ntfs and jfs from the monolithic grub-efi image, so we don't support them in Secure Boot any more. * These allow us to bump SBAT to "grub,5" (which we'll need as a minimum security level going forwards for Secure Boot) * Set Protected: yes for -signed packages so they cannot easily be removed * Misc salsa-ci updates for bookworm Those CVE fixes are marked as nodsa by the security team, hence aiming for bookworm-pu rather than going via -security. They've all been fixed in trixie and forky already, but we'd never uploaded similar fixes for bookworm. I'm about to bump the minimum revocations in shim for bookworm, trixie and forky - this will break SB for our existing bookworm signed grub-efi packages as they only have "grub,4". Hence this upload to make things work for bookworm again. I'm expecting this may be the last set of bookworm updates for shim and grub; let's get them to a state where they'll live as long as possible. I've tested the binaries here work on a range of machines; the backported patches included don't show any regressions. There *were* known regressions in the patches for NTFS, hence we've dropped those and disabled it for SB instead - similar to trixie and forky. grub2 (2.06-13+deb12u2) bookworm; urgency=medium [ Julian Andres Klode ] * Set Protected: yes for -signed packages so they cannot easily be removed * debian/patches: Backport to bookworm [ Felix Zielcke ] * Add salsa-ci.yml and disable blhc and reprotest pipelines. [ Luca Boccassi ] * salsa-ci: configure for stable builds [ Mate Kukri ] * Cherry-pick remaining XFS delta from 2.12 * Cherry-pick upstream vulnerability fixes * Cherry-pick extfs regression patch * Cherry-pick xfs regression patches * Bump SBAT level to grub,5 * fs/fat: Don't error when mtime is 0 (LP: #2098641) * SECURITY UPDATE: video/readers/jpeg: Do not permit duplicate SOF0 markers in JPEG - CVE-2024-45774 * SECURITY UPDATE: commands/extcmd: Missing check for failed allocation - CVE-2024-45775 * SECURITY UPDATE: gettext: Integer overflow leads to heap OOB write or read - CVE-2024-45776 * SECURITY UPDATE: gettext: Integer overflow leads to heap OOB write - CVE-2024-45777 * SECURITY UPDATE: fs/bfs: Integer overflow - CVE-2024-45778 * SECURITY UPDATE: fs/bfs: integer overflow leads to heap OOB read - CVE-2024-45779 * SECURITY UPDATE: fs/tar: Integer overflow leads to heap OOB write - CVE-2024-45780 * SECURITY UPDATE: fs/ufs: `strcpy` use leading to heap OOB write - CVE-2024-45781 * SECURITY UPDATE: fs/hfs: `strcpy` use leading to potential heap OOB write - CVE-2024-45782 * SECURITY UPDATE: fs/hfsplus: incorrect refcount handling leading to UAF - CVE-2024-45783 * SECURITY UPDATE: command/gpg: Use-after-free due to hooks not being removed on module unload - CVE-2025-0622 * SECURITY UPDATE: net: Out-of-bounds write in grub_net_search_config_file() - CVE-2025-0624 * SECURITY UPDATE: UFS: Integer overflow may lead to heap based out-of-bounds write when handling symlinks - CVE-2025-0677 * SECURITY UPDATE: squash4: Integer overflow may lead to heap based out-of-bounds write when reading data - CVE-2025-0678 * SECURITY UPDATE: reiserfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0684 * SECURITY UPDATE: jfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0685 * SECURITY UPDATE: romfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0686 * SECURITY UPDATE: udf: Heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution - CVE-2025-0689 *
Bug#1132510: marked as done (bookworm-pu: package grub2/2.06-13+deb12u2)
Your message dated Sat, 16 May 2026 11:07:42 + with message-id and subject line Released with 12.14 has caused the Debian Bug report #1132510, regarding bookworm-pu: package grub2/2.06-13+deb12u2 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 1132510: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132510 Debian Bug Tracking System Contact [email protected] with problems --- Begin Message --- Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: [email protected] Control: affects -1 + src:grub2 User: [email protected] Usertags: pu Hi! Along with the update to shim in bookworm, I'd like to update our grub2 packages. The key changes here are: * Backport lots of CVE fixes from the GRUB updates in 2025 * Disable ntfs and jfs from the monolithic grub-efi image, so we don't support them in Secure Boot any more. * These allow us to bump SBAT to "grub,5" (which we'll need as a minimum security level going forwards for Secure Boot) * Set Protected: yes for -signed packages so they cannot easily be removed * Misc salsa-ci updates for bookworm Those CVE fixes are marked as nodsa by the security team, hence aiming for bookworm-pu rather than going via -security. They've all been fixed in trixie and forky already, but we'd never uploaded similar fixes for bookworm. I'm about to bump the minimum revocations in shim for bookworm, trixie and forky - this will break SB for our existing bookworm signed grub-efi packages as they only have "grub,4". Hence this upload to make things work for bookworm again. I'm expecting this may be the last set of bookworm updates for shim and grub; let's get them to a state where they'll live as long as possible. I've tested the binaries here work on a range of machines; the backported patches included don't show any regressions. There *were* known regressions in the patches for NTFS, hence we've dropped those and disabled it for SB instead - similar to trixie and forky. grub2 (2.06-13+deb12u2) bookworm; urgency=medium [ Julian Andres Klode ] * Set Protected: yes for -signed packages so they cannot easily be removed * debian/patches: Backport to bookworm [ Felix Zielcke ] * Add salsa-ci.yml and disable blhc and reprotest pipelines. [ Luca Boccassi ] * salsa-ci: configure for stable builds [ Mate Kukri ] * Cherry-pick remaining XFS delta from 2.12 * Cherry-pick upstream vulnerability fixes * Cherry-pick extfs regression patch * Cherry-pick xfs regression patches * Bump SBAT level to grub,5 * fs/fat: Don't error when mtime is 0 (LP: #2098641) * SECURITY UPDATE: video/readers/jpeg: Do not permit duplicate SOF0 markers in JPEG - CVE-2024-45774 * SECURITY UPDATE: commands/extcmd: Missing check for failed allocation - CVE-2024-45775 * SECURITY UPDATE: gettext: Integer overflow leads to heap OOB write or read - CVE-2024-45776 * SECURITY UPDATE: gettext: Integer overflow leads to heap OOB write - CVE-2024-45777 * SECURITY UPDATE: fs/bfs: Integer overflow - CVE-2024-45778 * SECURITY UPDATE: fs/bfs: integer overflow leads to heap OOB read - CVE-2024-45779 * SECURITY UPDATE: fs/tar: Integer overflow leads to heap OOB write - CVE-2024-45780 * SECURITY UPDATE: fs/ufs: `strcpy` use leading to heap OOB write - CVE-2024-45781 * SECURITY UPDATE: fs/hfs: `strcpy` use leading to potential heap OOB write - CVE-2024-45782 * SECURITY UPDATE: fs/hfsplus: incorrect refcount handling leading to UAF - CVE-2024-45783 * SECURITY UPDATE: command/gpg: Use-after-free due to hooks not being removed on module unload - CVE-2025-0622 * SECURITY UPDATE: net: Out-of-bounds write in grub_net_search_config_file() - CVE-2025-0624 * SECURITY UPDATE: UFS: Integer overflow may lead to heap based out-of-bounds write when handling symlinks - CVE-2025-0677 * SECURITY UPDATE: squash4: Integer overflow may lead to heap based out-of-bounds write when reading data - CVE-2025-0678 * SECURITY UPDATE: reiserfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0684 * SECURITY UPDATE: jfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0685 * SECURITY UPDATE: romfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0686 * SECURITY UPDATE: udf: Heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution - CVE-2025-0689 *
Bug#1132510: marked as done (bookworm-pu: package grub2/2.06-13+deb12u2)
Your message dated Sat, 16 May 2026 11:07:42 + with message-id and subject line Released with 12.14 has caused the Debian Bug report #1132510, regarding bookworm-pu: package grub2/2.06-13+deb12u2 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 1132510: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132510 Debian Bug Tracking System Contact [email protected] with problems --- Begin Message --- Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: [email protected] Control: affects -1 + src:grub2 User: [email protected] Usertags: pu Hi! Along with the update to shim in bookworm, I'd like to update our grub2 packages. The key changes here are: * Backport lots of CVE fixes from the GRUB updates in 2025 * Disable ntfs and jfs from the monolithic grub-efi image, so we don't support them in Secure Boot any more. * These allow us to bump SBAT to "grub,5" (which we'll need as a minimum security level going forwards for Secure Boot) * Set Protected: yes for -signed packages so they cannot easily be removed * Misc salsa-ci updates for bookworm Those CVE fixes are marked as nodsa by the security team, hence aiming for bookworm-pu rather than going via -security. They've all been fixed in trixie and forky already, but we'd never uploaded similar fixes for bookworm. I'm about to bump the minimum revocations in shim for bookworm, trixie and forky - this will break SB for our existing bookworm signed grub-efi packages as they only have "grub,4". Hence this upload to make things work for bookworm again. I'm expecting this may be the last set of bookworm updates for shim and grub; let's get them to a state where they'll live as long as possible. I've tested the binaries here work on a range of machines; the backported patches included don't show any regressions. There *were* known regressions in the patches for NTFS, hence we've dropped those and disabled it for SB instead - similar to trixie and forky. grub2 (2.06-13+deb12u2) bookworm; urgency=medium [ Julian Andres Klode ] * Set Protected: yes for -signed packages so they cannot easily be removed * debian/patches: Backport to bookworm [ Felix Zielcke ] * Add salsa-ci.yml and disable blhc and reprotest pipelines. [ Luca Boccassi ] * salsa-ci: configure for stable builds [ Mate Kukri ] * Cherry-pick remaining XFS delta from 2.12 * Cherry-pick upstream vulnerability fixes * Cherry-pick extfs regression patch * Cherry-pick xfs regression patches * Bump SBAT level to grub,5 * fs/fat: Don't error when mtime is 0 (LP: #2098641) * SECURITY UPDATE: video/readers/jpeg: Do not permit duplicate SOF0 markers in JPEG - CVE-2024-45774 * SECURITY UPDATE: commands/extcmd: Missing check for failed allocation - CVE-2024-45775 * SECURITY UPDATE: gettext: Integer overflow leads to heap OOB write or read - CVE-2024-45776 * SECURITY UPDATE: gettext: Integer overflow leads to heap OOB write - CVE-2024-45777 * SECURITY UPDATE: fs/bfs: Integer overflow - CVE-2024-45778 * SECURITY UPDATE: fs/bfs: integer overflow leads to heap OOB read - CVE-2024-45779 * SECURITY UPDATE: fs/tar: Integer overflow leads to heap OOB write - CVE-2024-45780 * SECURITY UPDATE: fs/ufs: `strcpy` use leading to heap OOB write - CVE-2024-45781 * SECURITY UPDATE: fs/hfs: `strcpy` use leading to potential heap OOB write - CVE-2024-45782 * SECURITY UPDATE: fs/hfsplus: incorrect refcount handling leading to UAF - CVE-2024-45783 * SECURITY UPDATE: command/gpg: Use-after-free due to hooks not being removed on module unload - CVE-2025-0622 * SECURITY UPDATE: net: Out-of-bounds write in grub_net_search_config_file() - CVE-2025-0624 * SECURITY UPDATE: UFS: Integer overflow may lead to heap based out-of-bounds write when handling symlinks - CVE-2025-0677 * SECURITY UPDATE: squash4: Integer overflow may lead to heap based out-of-bounds write when reading data - CVE-2025-0678 * SECURITY UPDATE: reiserfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0684 * SECURITY UPDATE: jfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0685 * SECURITY UPDATE: romfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0686 * SECURITY UPDATE: udf: Heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution - CVE-2025-0689 *
Bug#1132510: marked as done (bookworm-pu: package grub2/2.06-13+deb12u2)
Your message dated Sat, 16 May 2026 11:07:42 + with message-id and subject line Released with 12.14 has caused the Debian Bug report #1132510, regarding bookworm-pu: package grub2/2.06-13+deb12u2 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 1132510: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132510 Debian Bug Tracking System Contact [email protected] with problems --- Begin Message --- Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: [email protected] Control: affects -1 + src:grub2 User: [email protected] Usertags: pu Hi! Along with the update to shim in bookworm, I'd like to update our grub2 packages. The key changes here are: * Backport lots of CVE fixes from the GRUB updates in 2025 * Disable ntfs and jfs from the monolithic grub-efi image, so we don't support them in Secure Boot any more. * These allow us to bump SBAT to "grub,5" (which we'll need as a minimum security level going forwards for Secure Boot) * Set Protected: yes for -signed packages so they cannot easily be removed * Misc salsa-ci updates for bookworm Those CVE fixes are marked as nodsa by the security team, hence aiming for bookworm-pu rather than going via -security. They've all been fixed in trixie and forky already, but we'd never uploaded similar fixes for bookworm. I'm about to bump the minimum revocations in shim for bookworm, trixie and forky - this will break SB for our existing bookworm signed grub-efi packages as they only have "grub,4". Hence this upload to make things work for bookworm again. I'm expecting this may be the last set of bookworm updates for shim and grub; let's get them to a state where they'll live as long as possible. I've tested the binaries here work on a range of machines; the backported patches included don't show any regressions. There *were* known regressions in the patches for NTFS, hence we've dropped those and disabled it for SB instead - similar to trixie and forky. grub2 (2.06-13+deb12u2) bookworm; urgency=medium [ Julian Andres Klode ] * Set Protected: yes for -signed packages so they cannot easily be removed * debian/patches: Backport to bookworm [ Felix Zielcke ] * Add salsa-ci.yml and disable blhc and reprotest pipelines. [ Luca Boccassi ] * salsa-ci: configure for stable builds [ Mate Kukri ] * Cherry-pick remaining XFS delta from 2.12 * Cherry-pick upstream vulnerability fixes * Cherry-pick extfs regression patch * Cherry-pick xfs regression patches * Bump SBAT level to grub,5 * fs/fat: Don't error when mtime is 0 (LP: #2098641) * SECURITY UPDATE: video/readers/jpeg: Do not permit duplicate SOF0 markers in JPEG - CVE-2024-45774 * SECURITY UPDATE: commands/extcmd: Missing check for failed allocation - CVE-2024-45775 * SECURITY UPDATE: gettext: Integer overflow leads to heap OOB write or read - CVE-2024-45776 * SECURITY UPDATE: gettext: Integer overflow leads to heap OOB write - CVE-2024-45777 * SECURITY UPDATE: fs/bfs: Integer overflow - CVE-2024-45778 * SECURITY UPDATE: fs/bfs: integer overflow leads to heap OOB read - CVE-2024-45779 * SECURITY UPDATE: fs/tar: Integer overflow leads to heap OOB write - CVE-2024-45780 * SECURITY UPDATE: fs/ufs: `strcpy` use leading to heap OOB write - CVE-2024-45781 * SECURITY UPDATE: fs/hfs: `strcpy` use leading to potential heap OOB write - CVE-2024-45782 * SECURITY UPDATE: fs/hfsplus: incorrect refcount handling leading to UAF - CVE-2024-45783 * SECURITY UPDATE: command/gpg: Use-after-free due to hooks not being removed on module unload - CVE-2025-0622 * SECURITY UPDATE: net: Out-of-bounds write in grub_net_search_config_file() - CVE-2025-0624 * SECURITY UPDATE: UFS: Integer overflow may lead to heap based out-of-bounds write when handling symlinks - CVE-2025-0677 * SECURITY UPDATE: squash4: Integer overflow may lead to heap based out-of-bounds write when reading data - CVE-2025-0678 * SECURITY UPDATE: reiserfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0684 * SECURITY UPDATE: jfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0685 * SECURITY UPDATE: romfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data - CVE-2025-0686 * SECURITY UPDATE: udf: Heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution - CVE-2025-0689 *

