Debian 9933 Published by

A grub2 security update has been released for Debian GNU/Linux 8 Extended LTS to address several issues that could result in crashes and potentially the execution of arbitrary code.



ELA-763-1 grub2 security update

Package : grub2
Version : 2.02~beta2-22+deb8u2 (jessie)

Several issues were found in GRUB2’s font handling code, which could result in crashes and potentially execution of arbitrary code. Further issues were found in image loading that could potentially lead to memory overflows. Please note that some integer overflow mitigations could not be applied because of builtin GCC functions which are only available in newer Debian versions. Only system administrators should be able to change grub2 fonts. If you use the default fonts, your system is not affected.

  ELA-763-1 grub2 security update