Re: grub2 CVEs in stable

2025-04-17 Thread Sylvain Beucler
Hi, I'm part of the Debian LTS Team and checking on our grub2 status. Are there any plans to work on a bullseye update? (asking because grub2 maintainers have done so in the past, and because grub2 is listed at lts-do-call-me:) https://salsa.debian.org/security-tracker-team/security-tracker/-/

Re: grub2 CVEs

2021-03-06 Thread Salvatore Bonaccorso
Hi, On Thu, Mar 04, 2021 at 02:21:04PM +0100, Sylvain Beucler wrote: > Are CVE-2021-20225 and CVE-2021-20233 specific to SecureBoot? They are only non-negligligible in SecureBoot context, or put otherwise without SecureBoot grub there is not crossing any reasonable trust boundary here. The short

Re: grub2 CVEs

2021-03-04 Thread Sylvain Beucler
Hi, Are CVE-2021-20225 and CVE-2021-20233 specific to SecureBoot? - Sylvain commit 77849e46951112dd87797b84485b40303e3c1239 Author: Utkarsh Gupta Date: Thu Mar 4 14:11:27 2021 +0530 Drop grub2 from dla-needed; ignored diff --git a/data/dla-needed.txt b/data/dla-needed.txt index 9b6576a