SUSE-SU-2022:2073-1

    Dashboard / Vulnerabilities / SUSE-SU-2022:2073-1

    SUSE-SU-2022:2073-1

    Published: 14 Jun 2022Last Modified: 4 Feb 2026

    Summary: Security update for grub2

    Details: This update for grub2 fixes the following issues: Security fixes and hardenings for boothole 3 / boothole 2022 (bsc#1198581) - CVE-2021-3695: Fixed that a crafted PNG grayscale image could lead to out-of-bounds write in heap (bsc#1191184) - CVE-2021-3696: Fixed that a crafted PNG image could lead to out-of-bound write during huffman table handling (bsc#1191185) - CVE-2021-3697: Fixed that a crafted JPEG image could lead to buffer underflow write in the heap (bsc#1191186) - CVE-2022-28733: Fixed fragmentation math in net/ip (bsc#1198460) - CVE-2022-28734: Fixed an out-of-bound write for split http headers (bsc#1198493) - CVE-2022-28735: Fixed some verifier framework changes (bsc#1198495) - CVE-2022-28736: Fixed a use-after-free in chainloader command (bsc#1198496) - Update SBAT security contact (bsc#1193282) - Bump grub's SBAT generation to 2 Other bugs fixed: - Use boot disks in OpenFirmware, fixing regression caused when the root LV is completely in the boot LUN (bsc#1197948) - Fix grub-install error when efi system partition is created as mdadm software raid1 device (bsc#1179981) (bsc#1195204) - Fix error in grub-install when linux root device is on lvm thin volume (bsc#1192622) (bsc#1191974) - Fix wrong default entry when booting snapshot (bsc#1159205) - Add support for simplefb (boo#1193532). - Fix error lvmid disk cannot be found after second disk added to the root volume group (bsc#1189874) (bsc#1071559) - Fix error /boot/grub2/locale/POSIX.gmo not found (bsc#1189769) - Fix unknown TPM error on buggy uefi firmware (bsc#1191504) - Fix arm64 kernel image not aligned on 64k boundary (bsc#1192522)

    Affected packages

    Package

    Name: grub2

    Purl: pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Micro%205.1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.04-150300.3.5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2022:2073-1 | CVE-DB