Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ff809535 by Emilio Pozuelo Monfort at 2026-07-15T13:14:28+02:00
Reserve DLA-4685-1 for grub2

- - - - -


2 changed files:

- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[15 Jul 2026] DLA-4685-1 grub2 - security update
+       {CVE-2024-45774 CVE-2024-45775 CVE-2024-45776 CVE-2024-45777 
CVE-2024-45778 CVE-2024-45779 CVE-2024-45780 CVE-2024-45781 CVE-2024-45782 
CVE-2024-45783 CVE-2025-0622 CVE-2025-0624 CVE-2025-0677 CVE-2025-0678 
CVE-2025-0684 CVE-2025-0685 CVE-2025-0686 CVE-2025-0689 CVE-2025-0690 
CVE-2025-1118 CVE-2025-1125}
+       [bullseye] - grub2 2.06-3~deb11u7
 [15 Jul 2026] DLA-4684-1 opam - security update
        {CVE-2026-57825}
        [bookworm] - opam 2.1.2-1+deb12u2


=====================================
data/dla-needed.txt
=====================================
@@ -232,32 +232,6 @@ golang-glog/bullseye
   NOTE: 20251107: 
https://buildd.debian.org/status/package.php?p=+golang-github-grpc-ecosystem-grpc-gateway&suite=bullseye-security
   NOTE: 20251107: Please coordinate with FTP masters to unblock the situation 
(Beuc/front-desk)
 --
-grub2/bullseye (Emilio)
-  NOTE: 20250105: Added by Front-Desk (apo)
-  NOTE: 20250105: high-profile package but not enough details yet. (apo)
-  NOTE: 20250219: New batch of 21 CVEs, with fixes (Beuc/front-desk)
-  NOTE: 20250405: Maintainers plan a bookworm PU in May, coordinate with them:
-  NOTE: 20250405: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1098319#25
-  NOTE: 20250415: Started a thread to document possible signatures/secureboot 
issues
-  NOTE: 20250415: https://lists.debian.org/debian-lts/2025/04/msg00036.html
-  NOTE: 20250417: Maintainers are preparing a bullseye update and recommend we
-  NOTE: 20250417: wait for the next point release due to regression risks:
-  NOTE: 20250417: https://salsa.debian.org/grub-team/grub/-/merge_requests/78
-  NOTE: 20250417: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1098319#35
-  NOTE: 20250522: Ping'd maintainer, secteam also ping'd privately before 
(Beuc/front-desk)
-  NOTE: 20250522: https://lists.debian.org/debian-lts/2025/05/msg00056.html
-  NOTE: 20250611: New maintainer ping from secteam (Beuc/front-desk)
-  NOTE: 20250809: New maintainer ping from secteam.
-  NOTE: 20251108: New maintainer ping from santiago (grub MR #77).
-  NOTE: 20251128: Maintainer unresponsive so far. New ping from secteam 
following new batch of CVEs.
-  NOTE: 20251129: Maintainer (jak) replied: work underway, proposed to skip 
next point release (2026-01, too soon)
-  NOTE: 20251129: also uncertainty on whether a shim/SBAT (revocation) update 
is feasible/needed.
-  NOTE: 20260406: grub2/bookworm approved https://bugs.debian.org/1132510 
(partial update)
-  NOTE: 20260407:  shim/bookworm approved https://bugs.debian.org/1131862 (but 
waiting for Microsoft signature)
-  NOTE: 20260529: called for testing: 
https://lists.debian.org/debian-lts/2026/05/msg00034.html (pochu)
-  NOTE: 20260715: grub2 was updated during the bookworm point release. doing a 
bit more
-  NOTE: 20260715: testing and will release it afterwards (pochu)
---
 gsasl (charles)
   NOTE: 20260618: Added by Front-Desk (charles)
   NOTE: 20260618: Bookworm patch proposed by maintainer, DSA 6348-1 already 
out.



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ff809535656173bbfaa41db1f522c2dd05c0d45f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ff809535656173bbfaa41db1f522c2dd05c0d45f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to