Bug 1182890 - (CVE-2021-3418) VUL-0: CVE-2021-3418: grub2: grub 2.05 reintroduced CVE-2020-15705
(CVE-2021-3418)
VUL-0: CVE-2021-3418: grub2: grub 2.05 reintroduced CVE-2020-15705
Status: RESOLVED UPSTREAM
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Michael Chang
Security Team bot
https://smash.suse.de/issue/278856/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-03-02 07:08 UTC by Marcus Meissner
Modified: 2021-09-07 12:48 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
0001-shim_lock-Only-skip-loading-shim_lock-verifier-with-.patch (9.52 KB, patch)
2021-03-02 07:34 UTC, Marcus Meissner
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Comment 5 Marcus Meissner 2021-03-02 07:34:59 UTC
Created attachment 846648 [details]
0001-shim_lock-Only-skip-loading-shim_lock-verifier-with-.patch

i think this is the patch that will get the CVE reference (currently has not)
Comment 7 Michael Chang 2021-03-02 12:23:27 UTC
The SLE release before SLE-15-SP1 didn't require this CVE fix, as they didn't use shim_lock verifier introduced in grub 2.04.
Comment 9 Marcus Meissner 2021-03-02 18:03:58 UTC
is public
Comment 10 Marcus Meissner 2021-09-07 12:48:09 UTC
closng