ELSA-2025-2867

ELSA-2025-2867 - grub2 security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2025-03-17

Description


[2.06-94.0.1]
- Rework the scripts to cover both in-place upgrade and update scenarios [Orabug: 36768566]
- Restore correct order of processing config files [Orabug: 36758359]
- Support setting custom kernels as default kernels [Orabug: 36043978]
- Bump SBAT metadata for grub to 3 [Orabug: 34872719]
- Fix CVE-2022-3775 [Orabug: 34871953]
- Enable signing for aarch64 EFI
- Fix signing certificate names
- Enable back btrfs grub module for EFI pre-built image [Orabug: 34360986]
- Replaced bugzilla.oracle.com references [Orabug: 34202300]
- Update provided certificate version to 202204 [JIRA: OLDIS-16371]
- Various coverity fixes [JIRA: OLDIS-16371]
- bump SBAT generation
- Update bug url [Orabug: 34202300]
- Revert provided certificate version back to 202102 [JIRA: OLDIS-16371]
- Update signing certificate [JIRA: OLDIS-16371]
- fix SBAT data [JIRA: OLDIS-16371]
- Update requires [JIRA: OLDIS-16371]
- Rebuild for SecureBoot signatures [Orabug: 33801813]
- Do not add shim and grub certificate deps for aarch64 packages [Orabug: 32670033]
- Update Oracle SBAT data [Orabug: 32670033]
- Use new signing certificate [Orabug: 32670033]
- honor /etc/sysconfig/kernel DEFAULTKERNEL setting for BLS [Orabug: 30643497]
- set EFIDIR as redhat for additional grub2 tools [Orabug: 29875597]
- Update upstream references [Orabug: 26388226]
- Insert Unbreakable Enterprise Kernel text into BLS config file [Orabug: 29417955]
- Put 'with' in menuentry instead of 'using' [Orabug: 18504756]
- Use different titles for UEK and RHCK kernels [Orabug: 18504756]

[2.06-94]
- CVE fixes
- Resolves: CVE-2025-0624
- Resolves: #RHEL-79842


Related CVEs


CVE-2025-0624

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) grub2-2.06-94.0.1.el9_5.src.rpm54be74d4178ba65b8c643be846121b1abc757e3de9ee87e5d90931f478e1138f-ol9_aarch64_baseos_latest
grub2-2.06-94.0.1.el9_5.src.rpm54be74d4178ba65b8c643be846121b1abc757e3de9ee87e5d90931f478e1138f-ol9_aarch64_u5_baseos_patch
grub2-common-2.06-94.0.1.el9_5.noarch.rpm62430fc324a641f1b07c52fbb6508029ed89955f88141f1d0e71069d28595248-ol9_aarch64_baseos_latest
grub2-common-2.06-94.0.1.el9_5.noarch.rpm62430fc324a641f1b07c52fbb6508029ed89955f88141f1d0e71069d28595248-ol9_aarch64_u5_baseos_patch
grub2-efi-aa64-2.06-94.0.1.el9_5.aarch64.rpm8e1cc10594a5fb09db2fd15b8c76cc0eaf5bc74e546ba8caba781bec093185aa-ol9_aarch64_baseos_latest
grub2-efi-aa64-2.06-94.0.1.el9_5.aarch64.rpm8e1cc10594a5fb09db2fd15b8c76cc0eaf5bc74e546ba8caba781bec093185aa-ol9_aarch64_u5_baseos_patch
grub2-efi-aa64-cdboot-2.06-94.0.1.el9_5.aarch64.rpm55d9e22bc45e11d00ee46a660adf97ce533bfe02a63b586d11110aedd138f892-ol9_aarch64_baseos_latest
grub2-efi-aa64-cdboot-2.06-94.0.1.el9_5.aarch64.rpm55d9e22bc45e11d00ee46a660adf97ce533bfe02a63b586d11110aedd138f892-ol9_aarch64_u5_baseos_patch
grub2-efi-aa64-modules-2.06-94.0.1.el9_5.noarch.rpm1cc7430390372a05acc07d74289c1dec46d1f217b34161794c4ce337304d572a-ol9_aarch64_baseos_latest
grub2-efi-aa64-modules-2.06-94.0.1.el9_5.noarch.rpm1cc7430390372a05acc07d74289c1dec46d1f217b34161794c4ce337304d572a-ol9_aarch64_u5_baseos_patch
grub2-efi-x64-modules-2.06-94.0.1.el9_5.noarch.rpmfdfdf3f2197a7e8328b62e72c0fed69e5f05475d025afda3f5394e5cca5b1ff7-ol9_aarch64_baseos_latest
grub2-efi-x64-modules-2.06-94.0.1.el9_5.noarch.rpmfdfdf3f2197a7e8328b62e72c0fed69e5f05475d025afda3f5394e5cca5b1ff7-ol9_aarch64_u5_baseos_patch
grub2-tools-2.06-94.0.1.el9_5.aarch64.rpm3fa10b4c0528644703e4ac4a505ad0576256d22c54f736e49d617a9651145340-ol9_aarch64_baseos_latest
grub2-tools-2.06-94.0.1.el9_5.aarch64.rpm3fa10b4c0528644703e4ac4a505ad0576256d22c54f736e49d617a9651145340-ol9_aarch64_u5_baseos_patch
grub2-tools-extra-2.06-94.0.1.el9_5.aarch64.rpmf87dee97951725febc0204bee9e1798a860f01f07a7008ec0e746ba5c17b811e-ol9_aarch64_baseos_latest
grub2-tools-extra-2.06-94.0.1.el9_5.aarch64.rpmf87dee97951725febc0204bee9e1798a860f01f07a7008ec0e746ba5c17b811e-ol9_aarch64_u5_baseos_patch
grub2-tools-minimal-2.06-94.0.1.el9_5.aarch64.rpm8060ad479768d9b12a5f1fa18948284a5f14354bd3bedf8645cddc46cd65a3e3-ol9_aarch64_baseos_latest
grub2-tools-minimal-2.06-94.0.1.el9_5.aarch64.rpm8060ad479768d9b12a5f1fa18948284a5f14354bd3bedf8645cddc46cd65a3e3-ol9_aarch64_u5_baseos_patch
Oracle Linux 9 (x86_64) grub2-2.06-94.0.1.el9_5.src.rpm54be74d4178ba65b8c643be846121b1abc757e3de9ee87e5d90931f478e1138f-ol9_x86_64_baseos_latest
grub2-2.06-94.0.1.el9_5.src.rpm54be74d4178ba65b8c643be846121b1abc757e3de9ee87e5d90931f478e1138f-ol9_x86_64_u5_baseos_patch
grub2-common-2.06-94.0.1.el9_5.noarch.rpm62430fc324a641f1b07c52fbb6508029ed89955f88141f1d0e71069d28595248-ol9_x86_64_baseos_latest
grub2-common-2.06-94.0.1.el9_5.noarch.rpm62430fc324a641f1b07c52fbb6508029ed89955f88141f1d0e71069d28595248-ol9_x86_64_u5_baseos_patch
grub2-efi-aa64-modules-2.06-94.0.1.el9_5.noarch.rpm1cc7430390372a05acc07d74289c1dec46d1f217b34161794c4ce337304d572a-ol9_x86_64_baseos_latest
grub2-efi-aa64-modules-2.06-94.0.1.el9_5.noarch.rpm1cc7430390372a05acc07d74289c1dec46d1f217b34161794c4ce337304d572a-ol9_x86_64_u5_baseos_patch
grub2-efi-x64-2.06-94.0.1.el9_5.x86_64.rpm2472e22ab12cbf699818de229e4ee70791e3f1694cd777d1d62838d98a4f7059-ol9_x86_64_baseos_latest
grub2-efi-x64-2.06-94.0.1.el9_5.x86_64.rpm2472e22ab12cbf699818de229e4ee70791e3f1694cd777d1d62838d98a4f7059-ol9_x86_64_u5_baseos_patch
grub2-efi-x64-cdboot-2.06-94.0.1.el9_5.x86_64.rpma9bef4487901c71e2ba19058436aecaaa5f7d033daad1228072a037c76861578-ol9_x86_64_baseos_latest
grub2-efi-x64-cdboot-2.06-94.0.1.el9_5.x86_64.rpma9bef4487901c71e2ba19058436aecaaa5f7d033daad1228072a037c76861578-ol9_x86_64_u5_baseos_patch
grub2-efi-x64-modules-2.06-94.0.1.el9_5.noarch.rpmfdfdf3f2197a7e8328b62e72c0fed69e5f05475d025afda3f5394e5cca5b1ff7-ol9_x86_64_baseos_latest
grub2-efi-x64-modules-2.06-94.0.1.el9_5.noarch.rpmfdfdf3f2197a7e8328b62e72c0fed69e5f05475d025afda3f5394e5cca5b1ff7-ol9_x86_64_u5_baseos_patch
grub2-pc-2.06-94.0.1.el9_5.x86_64.rpmabd0edaed49acdd84f336561584ccebfedaeb311ca9c3f3d67042dee4a444a12-ol9_x86_64_baseos_latest
grub2-pc-2.06-94.0.1.el9_5.x86_64.rpmabd0edaed49acdd84f336561584ccebfedaeb311ca9c3f3d67042dee4a444a12-ol9_x86_64_u5_baseos_patch
grub2-pc-modules-2.06-94.0.1.el9_5.noarch.rpm58c7d6809f32c10da8af3cd68d38745188bcdaf47fb086414dbe1fc18b67ec93-ol9_x86_64_baseos_latest
grub2-pc-modules-2.06-94.0.1.el9_5.noarch.rpm58c7d6809f32c10da8af3cd68d38745188bcdaf47fb086414dbe1fc18b67ec93-ol9_x86_64_u5_baseos_patch
grub2-tools-2.06-94.0.1.el9_5.x86_64.rpm54c906d38c911a806a643eda9811f56345298298641aafd10f94d7c4e34fa138-ol9_x86_64_baseos_latest
grub2-tools-2.06-94.0.1.el9_5.x86_64.rpm54c906d38c911a806a643eda9811f56345298298641aafd10f94d7c4e34fa138-ol9_x86_64_u5_baseos_patch
grub2-tools-efi-2.06-94.0.1.el9_5.x86_64.rpme4eba196d4e2499a6f808be10f0e25a02cd0e970447133642389009858e03d90-ol9_x86_64_baseos_latest
grub2-tools-efi-2.06-94.0.1.el9_5.x86_64.rpme4eba196d4e2499a6f808be10f0e25a02cd0e970447133642389009858e03d90-ol9_x86_64_u5_baseos_patch
grub2-tools-extra-2.06-94.0.1.el9_5.x86_64.rpm700b5ae304fc7ec91ab91ebee48de09940b7a6dd039c2df7ad877fc74d78709e-ol9_x86_64_baseos_latest
grub2-tools-extra-2.06-94.0.1.el9_5.x86_64.rpm700b5ae304fc7ec91ab91ebee48de09940b7a6dd039c2df7ad877fc74d78709e-ol9_x86_64_u5_baseos_patch
grub2-tools-minimal-2.06-94.0.1.el9_5.x86_64.rpmf2f3461b7adf69c36f780b2fc8c85fd2a305fa1b4d6838823b486527b4fae6b4-ol9_x86_64_baseos_latest
grub2-tools-minimal-2.06-94.0.1.el9_5.x86_64.rpmf2f3461b7adf69c36f780b2fc8c85fd2a305fa1b4d6838823b486527b4fae6b4-ol9_x86_64_u5_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete