ELSA-2022-5095

ELSA-2022-5095 - grub2, mokutil, shim, and shim-unsigned-x64 security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2022-07-04

Description


[2.02-123.0.4.el8_6.8]
- enable multiboot2 [Orabug: 34285558]
- backport arm64: Fix EFI loader kernel image allocation [Orabug: 33702462]
- backport Arm: check for the PE magic for the compiled arch [Orabug: 33702462]
- Backport some better script logic for BTRFS support [Orabug: 32448171]
- Do not add shim and grub certificate deps for aarch64 packages [Orabug: 32670033]
- Update Oracle SBAT data [Orabug: 32670033]
- Use new signing certificate [Orabug: 32670033]
- Fix various coverity issues [Orabug: 32530657]
- Set proper blsdir if /boot is on btrfs rootfs [Orabug: 32063327]
- Add CVE-2020-15706, CVE-2020-15707 to the list [Orabug: 31225072]
- honor /etc/sysconfig/kernel DEFAULTKERNEL setting for BLS [Orabug: 30643497]
- set EFIDIR as redhat for additional grub2 tools [Orabug: 29875597]
- Update upstream references [Orabug: 26388226]
- Insert Unbreakable Enterprise Kernel text into BLS config file [Orabug: 29417955]
- fix symlink removal scriptlet, to be executed only on removal [Orabug: 19231481]
- Fix comparison in patch for 18504756
- Remove symlink to grub environment file during uninstall on EFI platforms [Orabug: 19231481]
- Put 'with' in menuentry instead of 'using' [Orabug: 18504756]
- Use different titles for UEK and RHCK kernels [Orabug: 18504756]

[2.06-123.el8_6.8]
- CVE fixes for 2022-06-07
- CVE-2022-28736 CVE-2022-28735 CVE-2022-28734 CVE-2022-28733
- CVE-2021-3697 CVE-2021-3696 CVE-2021-3695
- Resolves: #2031899


Related CVEs


CVE-2022-28733
CVE-2022-28735
CVE-2021-3695
CVE-2021-3697
CVE-2022-28736
CVE-2022-28737
CVE-2021-3696
CVE-2022-28734

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) grub2-2.02-123.0.7.el8_6.8.src.rpme7bc618383c6ddc5411a2f7fc4f6f0c2-ol8_aarch64_baseos_latest
grub2-2.02-123.0.7.el8_6.8.src.rpme7bc618383c6ddc5411a2f7fc4f6f0c2-ol8_aarch64_u6_baseos_patch
grub2-common-2.02-123.0.7.el8_6.8.noarch.rpm126e24ab5eef87f73586026241bb6078-ol8_aarch64_baseos_latest
grub2-common-2.02-123.0.7.el8_6.8.noarch.rpm126e24ab5eef87f73586026241bb6078-ol8_aarch64_u6_baseos_patch
grub2-efi-aa64-2.02-123.0.7.el8_6.8.aarch64.rpmddfd018b14540c562c8f0dbeed1aecce-ol8_aarch64_baseos_latest
grub2-efi-aa64-2.02-123.0.7.el8_6.8.aarch64.rpmddfd018b14540c562c8f0dbeed1aecce-ol8_aarch64_u6_baseos_patch
grub2-efi-aa64-cdboot-2.02-123.0.7.el8_6.8.aarch64.rpmc4400535552bca037922eaac0e699ab8-ol8_aarch64_baseos_latest
grub2-efi-aa64-cdboot-2.02-123.0.7.el8_6.8.aarch64.rpmc4400535552bca037922eaac0e699ab8-ol8_aarch64_u6_baseos_patch
grub2-efi-aa64-modules-2.02-123.0.7.el8_6.8.noarch.rpm3b05ac2db5a0a9cf04d9521ce61967cb-ol8_aarch64_baseos_latest
grub2-efi-aa64-modules-2.02-123.0.7.el8_6.8.noarch.rpm3b05ac2db5a0a9cf04d9521ce61967cb-ol8_aarch64_u6_baseos_patch
grub2-efi-ia32-modules-2.02-123.0.7.el8_6.8.noarch.rpm8c977e254ea1e963e09583ae731d73a0-ol8_aarch64_baseos_latest
grub2-efi-ia32-modules-2.02-123.0.7.el8_6.8.noarch.rpm8c977e254ea1e963e09583ae731d73a0-ol8_aarch64_u6_baseos_patch
grub2-efi-x64-modules-2.02-123.0.7.el8_6.8.noarch.rpm50ce29da5f2ae81b0fc2a47b85ffe3de-ol8_aarch64_baseos_latest
grub2-efi-x64-modules-2.02-123.0.7.el8_6.8.noarch.rpm50ce29da5f2ae81b0fc2a47b85ffe3de-ol8_aarch64_u6_baseos_patch
grub2-pc-modules-2.02-123.0.7.el8_6.8.noarch.rpm7278ea299aa386fcc0ae164db7a7ec50-ol8_aarch64_baseos_latest
grub2-pc-modules-2.02-123.0.7.el8_6.8.noarch.rpm7278ea299aa386fcc0ae164db7a7ec50-ol8_aarch64_u6_baseos_patch
grub2-tools-2.02-123.0.7.el8_6.8.aarch64.rpm38d141da35ff125382ebe39c75790192-ol8_aarch64_baseos_latest
grub2-tools-2.02-123.0.7.el8_6.8.aarch64.rpm38d141da35ff125382ebe39c75790192-ol8_aarch64_u6_baseos_patch
grub2-tools-extra-2.02-123.0.7.el8_6.8.aarch64.rpm716bcdc3bfca58f6a11a77ed199d9ee9-ol8_aarch64_baseos_latest
grub2-tools-extra-2.02-123.0.7.el8_6.8.aarch64.rpm716bcdc3bfca58f6a11a77ed199d9ee9-ol8_aarch64_u6_baseos_patch
grub2-tools-minimal-2.02-123.0.7.el8_6.8.aarch64.rpm091f7f1fe4b0b09afe1d25e036b624fd-ol8_aarch64_baseos_latest
grub2-tools-minimal-2.02-123.0.7.el8_6.8.aarch64.rpm091f7f1fe4b0b09afe1d25e036b624fd-ol8_aarch64_u6_baseos_patch
Oracle Linux 8 (x86_64) grub2-2.02-123.0.7.el8_6.8.src.rpme7bc618383c6ddc5411a2f7fc4f6f0c2-ol8_x86_64_baseos_latest
grub2-2.02-123.0.7.el8_6.8.src.rpme7bc618383c6ddc5411a2f7fc4f6f0c2-ol8_x86_64_u6_baseos_patch
grub2-common-2.02-123.0.7.el8_6.8.noarch.rpm126e24ab5eef87f73586026241bb6078-ol8_x86_64_baseos_latest
grub2-common-2.02-123.0.7.el8_6.8.noarch.rpm126e24ab5eef87f73586026241bb6078-ol8_x86_64_u6_baseos_patch
grub2-efi-aa64-modules-2.02-123.0.7.el8_6.8.noarch.rpm3b05ac2db5a0a9cf04d9521ce61967cb-ol8_x86_64_baseos_latest
grub2-efi-aa64-modules-2.02-123.0.7.el8_6.8.noarch.rpm3b05ac2db5a0a9cf04d9521ce61967cb-ol8_x86_64_u6_baseos_patch
grub2-efi-ia32-2.02-123.0.7.el8_6.8.x86_64.rpmbd3d086888725ffb4c270459f7a28b48-ol8_x86_64_baseos_latest
grub2-efi-ia32-2.02-123.0.7.el8_6.8.x86_64.rpmbd3d086888725ffb4c270459f7a28b48-ol8_x86_64_u6_baseos_patch
grub2-efi-ia32-cdboot-2.02-123.0.7.el8_6.8.x86_64.rpm6b80c2fdea6a494f5d7c6ee724f925d4-ol8_x86_64_baseos_latest
grub2-efi-ia32-cdboot-2.02-123.0.7.el8_6.8.x86_64.rpm6b80c2fdea6a494f5d7c6ee724f925d4-ol8_x86_64_u6_baseos_patch
grub2-efi-ia32-modules-2.02-123.0.7.el8_6.8.noarch.rpm8c977e254ea1e963e09583ae731d73a0-ol8_x86_64_baseos_latest
grub2-efi-ia32-modules-2.02-123.0.7.el8_6.8.noarch.rpm8c977e254ea1e963e09583ae731d73a0-ol8_x86_64_u6_baseos_patch
grub2-efi-x64-2.02-123.0.7.el8_6.8.x86_64.rpmdfd95d9da7068c926dc68684820123aa-ol8_x86_64_baseos_latest
grub2-efi-x64-2.02-123.0.7.el8_6.8.x86_64.rpmdfd95d9da7068c926dc68684820123aa-ol8_x86_64_u6_baseos_patch
grub2-efi-x64-cdboot-2.02-123.0.7.el8_6.8.x86_64.rpm974e9d80491bfce3f9be8c6b0dc9c469-ol8_x86_64_baseos_latest
grub2-efi-x64-cdboot-2.02-123.0.7.el8_6.8.x86_64.rpm974e9d80491bfce3f9be8c6b0dc9c469-ol8_x86_64_u6_baseos_patch
grub2-efi-x64-modules-2.02-123.0.7.el8_6.8.noarch.rpm50ce29da5f2ae81b0fc2a47b85ffe3de-ol8_x86_64_baseos_latest
grub2-efi-x64-modules-2.02-123.0.7.el8_6.8.noarch.rpm50ce29da5f2ae81b0fc2a47b85ffe3de-ol8_x86_64_u6_baseos_patch
grub2-pc-2.02-123.0.7.el8_6.8.x86_64.rpm58ce48ec387bbe4668d72504dad013e7-ol8_x86_64_baseos_latest
grub2-pc-2.02-123.0.7.el8_6.8.x86_64.rpm58ce48ec387bbe4668d72504dad013e7-ol8_x86_64_u6_baseos_patch
grub2-pc-modules-2.02-123.0.7.el8_6.8.noarch.rpm7278ea299aa386fcc0ae164db7a7ec50-ol8_x86_64_baseos_latest
grub2-pc-modules-2.02-123.0.7.el8_6.8.noarch.rpm7278ea299aa386fcc0ae164db7a7ec50-ol8_x86_64_u6_baseos_patch
grub2-tools-2.02-123.0.7.el8_6.8.x86_64.rpmb4dc8eaa7530e512dd52768793c86cb3-ol8_x86_64_baseos_latest
grub2-tools-2.02-123.0.7.el8_6.8.x86_64.rpmb4dc8eaa7530e512dd52768793c86cb3-ol8_x86_64_u6_baseos_patch
grub2-tools-efi-2.02-123.0.7.el8_6.8.x86_64.rpmeee5f11b18ab7c38dc0072c9b8472850-ol8_x86_64_baseos_latest
grub2-tools-efi-2.02-123.0.7.el8_6.8.x86_64.rpmeee5f11b18ab7c38dc0072c9b8472850-ol8_x86_64_u6_baseos_patch
grub2-tools-extra-2.02-123.0.7.el8_6.8.x86_64.rpm64313dcc108224ad0db49d29d5e75ee8-ol8_x86_64_baseos_latest
grub2-tools-extra-2.02-123.0.7.el8_6.8.x86_64.rpm64313dcc108224ad0db49d29d5e75ee8-ol8_x86_64_u6_baseos_patch
grub2-tools-minimal-2.02-123.0.7.el8_6.8.x86_64.rpma49ba951aef5a129b357ed8e60f1e45c-ol8_x86_64_baseos_latest
grub2-tools-minimal-2.02-123.0.7.el8_6.8.x86_64.rpma49ba951aef5a129b357ed8e60f1e45c-ol8_x86_64_u6_baseos_patch


This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections:

software.hardware.complete