Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ff809535 by Emilio Pozuelo Monfort at 2026-07-15T13:14:28+02:00
Reserve DLA-4685-1 for grub2
- - - - -
2 changed files:
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[15 Jul 2026] DLA-4685-1 grub2 - security update
+ {CVE-2024-45774 CVE-2024-45775 CVE-2024-45776 CVE-2024-45777
CVE-2024-45778 CVE-2024-45779 CVE-2024-45780 CVE-2024-45781 CVE-2024-45782
CVE-2024-45783 CVE-2025-0622 CVE-2025-0624 CVE-2025-0677 CVE-2025-0678
CVE-2025-0684 CVE-2025-0685 CVE-2025-0686 CVE-2025-0689 CVE-2025-0690
CVE-2025-1118 CVE-2025-1125}
+ [bullseye] - grub2 2.06-3~deb11u7
[15 Jul 2026] DLA-4684-1 opam - security update
{CVE-2026-57825}
[bookworm] - opam 2.1.2-1+deb12u2
=====================================
data/dla-needed.txt
=====================================
@@ -232,32 +232,6 @@ golang-glog/bullseye
NOTE: 20251107:
https://buildd.debian.org/status/package.php?p=+golang-github-grpc-ecosystem-grpc-gateway&suite=bullseye-security
NOTE: 20251107: Please coordinate with FTP masters to unblock the situation
(Beuc/front-desk)
--
-grub2/bullseye (Emilio)
- NOTE: 20250105: Added by Front-Desk (apo)
- NOTE: 20250105: high-profile package but not enough details yet. (apo)
- NOTE: 20250219: New batch of 21 CVEs, with fixes (Beuc/front-desk)
- NOTE: 20250405: Maintainers plan a bookworm PU in May, coordinate with them:
- NOTE: 20250405: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1098319#25
- NOTE: 20250415: Started a thread to document possible signatures/secureboot
issues
- NOTE: 20250415: https://lists.debian.org/debian-lts/2025/04/msg00036.html
- NOTE: 20250417: Maintainers are preparing a bullseye update and recommend we
- NOTE: 20250417: wait for the next point release due to regression risks:
- NOTE: 20250417: https://salsa.debian.org/grub-team/grub/-/merge_requests/78
- NOTE: 20250417: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1098319#35
- NOTE: 20250522: Ping'd maintainer, secteam also ping'd privately before
(Beuc/front-desk)
- NOTE: 20250522: https://lists.debian.org/debian-lts/2025/05/msg00056.html
- NOTE: 20250611: New maintainer ping from secteam (Beuc/front-desk)
- NOTE: 20250809: New maintainer ping from secteam.
- NOTE: 20251108: New maintainer ping from santiago (grub MR #77).
- NOTE: 20251128: Maintainer unresponsive so far. New ping from secteam
following new batch of CVEs.
- NOTE: 20251129: Maintainer (jak) replied: work underway, proposed to skip
next point release (2026-01, too soon)
- NOTE: 20251129: also uncertainty on whether a shim/SBAT (revocation) update
is feasible/needed.
- NOTE: 20260406: grub2/bookworm approved https://bugs.debian.org/1132510
(partial update)
- NOTE: 20260407: shim/bookworm approved https://bugs.debian.org/1131862 (but
waiting for Microsoft signature)
- NOTE: 20260529: called for testing:
https://lists.debian.org/debian-lts/2026/05/msg00034.html (pochu)
- NOTE: 20260715: grub2 was updated during the bookworm point release. doing a
bit more
- NOTE: 20260715: testing and will release it afterwards (pochu)
---
gsasl (charles)
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Bookworm patch proposed by maintainer, DSA 6348-1 already
out.
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ff809535656173bbfaa41db1f522c2dd05c0d45f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ff809535656173bbfaa41db1f522c2dd05c0d45f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits