{"id":"SUSE-SU-2025:01961-1","summary":"Security update for grub2","details":"This update for grub2 fixes the following issues:\n\n- CVE-2023-4692: nfs: out-of-bounds write at fs/ntfs.c may lead to unsigned code execution (bsc#1215935).\n- CVE-2023-4693: nfs: out-of-bounds read at fs/ntfs.c (bsc#1215936).\n- CVE-2024-45774: heap overflows in JPEG parser (bsc#1233609).\n- CVE-2024-45775: missing NULL check in extcmd parser (bsc#1233610).\n- CVE-2024-45776: overflow in .MO file (gettext) handling (bsc#1233612).\n- CVE-2024-45777: integer overflow in gettext (bsc#1233613).\n- CVE-2024-45778: bfs filesystem not fuzzing stable (bsc#1233606).\n- CVE-2024-45779: bfs: heap overflow (bsc#1233608).\n- CVE-2024-45780: overflow in tar/cpio (bsc#1233614).\n- CVE-2024-45781: ufs: strcpy overflow (bsc#1233617).\n- CVE-2024-45782: hfs: strcpy overflow (bsc#1233615).\n- CVE-2024-45783: hfsplus: refcount overflow (bsc#1233616).\n- CVE-2024-56737: heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem (bsc#1234958).\n- CVE-2025-0622: command/gpg: Use-after-free due to hooks not being removed on module unload (bsc#1236317).\n- CVE-2025-0624: net: Out-of-bounds write in grub_net_search_config_file() (bsc#1236316).\n- CVE-2025-0677: ufs: Integer overflow may lead to heap based out-of-bounds write when handling symlinks (bsc#1237002).\n- CVE-2025-0678: squash4: Integer overflow may lead to heap based out-of-bounds write when reading data (bsc#1237006).\n- CVE-2025-0684: reiserfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data (bsc#1237008).\n- CVE-2025-0685: jfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data (bsc#1237009).\n- CVE-2025-0686: romfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data (bsc#1237010).\n- CVE-2025-0689: udf: Heap based buffer overflow  in grub_udf_read_block() may lead to arbitrary code execution (bsc#1237011).\n- CVE-2025-0690: read: Integer overflow may lead to out-of-bounds write (bsc#1237012).\n- CVE-2025-1118: commands/dump: The dump command is not in lockdown when secure boot is enabled (bsc#1237013).\n- CVE-2025-1125: fs/hfs: Interger overflow may lead to heap based out-of-bounds write (bsc#1237014).\n\nOther bugfixes:\n\n- Bump upstream SBAT generation to 5\n","modified":"2026-03-23T04:46:24.715250Z","published":"2025-06-16T10:03:22Z","related":["CVE-2023-4692","CVE-2023-4693","CVE-2024-45774","CVE-2024-45775","CVE-2024-45776","CVE-2024-45777","CVE-2024-45778","CVE-2024-45779","CVE-2024-45780","CVE-2024-45781","CVE-2024-45782","CVE-2024-45783","CVE-2024-56737","CVE-2025-0622","CVE-2025-0624","CVE-2025-0677","CVE-2025-0678","CVE-2025-0684","CVE-2025-0685","CVE-2025-0686","CVE-2025-0689","CVE-2025-0690","CVE-2025-1118","CVE-2025-1125"],"upstream":["CVE-2023-4692","CVE-2023-4693","CVE-2024-45774","CVE-2024-45775","CVE-2024-45776","CVE-2024-45777","CVE-2024-45778","CVE-2024-45779","CVE-2024-45780","CVE-2024-45781","CVE-2024-45782","CVE-2024-45783","CVE-2024-56737","CVE-2025-0622","CVE-2025-0624","CVE-2025-0677","CVE-2025-0678","CVE-2025-0684","CVE-2025-0685","CVE-2025-0686","CVE-2025-0689","CVE-2025-0690","CVE-2025-1118","CVE-2025-1125"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202501961-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215935"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215936"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233606"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233608"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233609"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233610"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233612"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233613"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233614"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233615"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233616"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233617"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234958"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236316"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236317"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237002"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237006"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237008"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237009"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237010"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237011"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237012"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237013"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237014"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4692"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4693"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45775"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45776"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45777"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45778"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45779"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45780"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45781"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45782"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45783"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-56737"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-0622"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-0624"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-0677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-0678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-0684"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-0685"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-0686"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-0689"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-0690"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-1118"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-1125"}],"affected":[{"package":{"name":"grub2","ecosystem":"SUSE:Linux Enterprise Micro 5.1","purl":"pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Micro%205.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.04-150300.3.11.1"}]}],"ecosystem_specific":{"binaries":[{"grub2-arm64-efi":"2.04-150300.3.11.1","grub2-i386-pc":"2.04-150300.3.11.1","grub2-s390x-emu":"2.04-150300.3.11.1","grub2-snapper-plugin":"2.04-150300.3.11.1","grub2-x86_64-efi":"2.04-150300.3.11.1","grub2-x86_64-xen":"2.04-150300.3.11.1","grub2":"2.04-150300.3.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:01961-1.json"}}],"schema_version":"1.7.5"}