ELSA-2020-5790

ELSA-2020-5790 - grub2 security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2020-07-29

Description


[2.02-81.0.4]
- Fix CVE-2020-10713, CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311,
CVE-2020-15705, CVE-2020-15706, CVE-2020-15707 [Orabug: 31225072]
- Update signing certificate for efi binaries

[2.02-0.81.0.2]
- Enable common subpackage build for aarch64
- Disable RHEL patch 0183-efinet-retransmit-if-our-device-is-busy.patch to comply with UEFI spec
- increase timeout to 10ms in efinet.c, [Orabug: 27982684]

[2.02-0.81.0.1]
- Update upstream references [Orabug: 30138841]
- build with the updated Oracle certificate
- Restore symlink to grub environment file, that was removed during grub2-efi update
if grub2 package is also installed on UEFI machines [Orabug: 27345750]
- fix symlink removal scriptlet, to be executed only on removal [Orabug: 19231481]
- Pack files in efidir with disabled rpm verification [Orabug: 27166026]
- Fix comparison in patch for [Orabug: 18504756]
- Remove symlink to grub environment file during uninstall on EFI platforms [Orabug: 19231481]
- replace dynamic EFI boot folder path generation with predefined 'redhat' (Alex Burmashev)
- update Oracle Linux certificates (Alexey Petrenko)
- Put 'with' in menuentry instead of 'using' [Orabug: 18504756]
- Use different titles for UEK and RHCK kernels [Orabug: 18504756]
- changed efidir with 0700 access rights, redhat chose another approach in rhbz#1496952, [Orabug: 28622344]
- revert orabug [Orabug: 27166026] changes


Related CVEs


CVE-2020-10713
CVE-2020-14308
CVE-2020-14309
CVE-2020-14311
CVE-2020-15706
CVE-2020-15707
CVE-2020-14310
CVE-2020-15705

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) grub2-2.02-0.81.0.4.el7.src.rpm2f9ed4534c47595e96fbdac77e049b1bELBA-2021-9158
grub2-2.02-0.81.0.4.el7.aarch64.rpm443d4282f86fad438bdc87dc2d4d29cbELBA-2021-9158
grub2-efi-aa64-2.02-0.81.0.4.el7.aarch64.rpme94d059f665a2f4624ee0a379244b705ELBA-2021-9158
grub2-efi-aa64-cdboot-2.02-0.81.0.4.el7.aarch64.rpm80b951f74dd9395b160d70d8a4348431ELBA-2021-9158
grub2-tools-2.02-0.81.0.4.el7.aarch64.rpmd34bf733fde849c0cfbb892525fb899dELBA-2021-9158
grub2-tools-extra-2.02-0.81.0.4.el7.aarch64.rpm96c5e95511218c9b5bbf67af316cb68aELBA-2021-9158
grub2-tools-minimal-2.02-0.81.0.4.el7.aarch64.rpm4ed4c1b729d337d353861e05d49fee17ELBA-2021-9158



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete