This bug was fixed in the package grub2-unsigned - 2.06-2ubuntu14
--------------- grub2-unsigned (2.06-2ubuntu14) kinetic; urgency=medium
* SECURITY UPDATE: Fix out of bounds writes due specially crafted fonts. - add debian/patches/font-Fix-several-integer-overflows-in-grub_font_construct.patch - add debian/patches/font-Fix-an-integer-underflow-in-blit_comb.patch - CVE-2022-2601, CVE-2022-3775 - LP: #1996950 * Fix various issues as a result of fuzzing, static analysis and code review: - add debian/patches/font-Reject-glyphs-exceeds-font-max_glyph_width-or-font-m.patch - add debian/patches/font-Fix-size-overflow-in-grub_font_get_glyph_internal.patch - add debian/patchces/font-Remove-grub_font_dup_glyph.patch - add debian/patches/font-Fix-integer-overflow-in-ensure_comb_space.patch - add debian/patches/font-Fix-integer-overflow-in-BMP-index.patch - add debian/patches/font-Fix-integer-underflow-in-binary-search-of-char-index.patch - add debian/patches/fbutil-Fix-integer-overflow.patch - add debian/patches/font-Harden-grub_font_blit_glyph-and-grub_font_blit_glyph.patch - add debian/patches/font-Assign-null_font-to-glyphs-in-ascii_font_glyph.patch - add debian/patches/normal-charset-Fix-an-integer-overflow-in-grub_unicode_ag.patch * Enforce verification of fonts when secure boot is enabled: - add debian/patches/kern-efi-sb-Enforce-verification-of-font-files.patch * Bundle unicode.pf2 in a squashfs memdisk attached to the signed EFI binary - update debian/control - update debian/build-efi-image - add debian/patches/font-Try-opening-fonts-from-the-bundled-memdisk.patch * Fix LP: #1997006 - add support for performing measurements to RTMRs - add debian/patches/commands-efi-tpm-Refine-the-status-of-log-event.patch - add debian/patches/commands-efi-tpm-Use-grub_strcpy-instead-of-grub_memcpy.patch - add debian/patches/efi-tpm-Add-EFI_CC_MEASUREMENT_PROTOCOL-support.patch * Fix the squashfs tests during the build - remove debian/patches/ubuntu-fix-reproducible-squashfs-test.patch - add debian/patches/tests-Explicitly-unset-SOURCE_DATE_EPOCH-before-running-f.patch * Bump SBAT generation: - update debian/sbat.ubuntu.csv.in * Source package generated from src:grub2 using make -f ./debian/rules generate-grub2-unsigned
-- Chris Coulson <email address hidden> Wed, 16 Nov 2022 14:40:42 +0000
This bug was fixed in the package grub2-unsigned - 2.06-2ubuntu14
---------------
grub2-unsigned (2.06-2ubuntu14) kinetic; urgency=medium
* SECURITY UPDATE: Fix out of bounds writes due specially crafted fonts. patches/ font-Fix- several- integer- overflows- in-grub_ font_construct. patch patches/ font-Fix- an-integer- underflow- in-blit_ comb.patch patches/ font-Reject- glyphs- exceeds- font-max_ glyph_width- or-font- m.patch patches/ font-Fix- size-overflow- in-grub_ font_get_ glyph_internal. patch patchces/ font-Remove- grub_font_ dup_glyph. patch patches/ font-Fix- integer- overflow- in-ensure_ comb_space. patch patches/ font-Fix- integer- overflow- in-BMP- index.patch patches/ font-Fix- integer- underflow- in-binary- search- of-char- index.patch patches/ fbutil- Fix-integer- overflow. patch patches/ font-Harden- grub_font_ blit_glyph- and-grub_ font_blit_ glyph.patch patches/ font-Assign- null_font- to-glyphs- in-ascii_ font_glyph. patch patches/ normal- charset- Fix-an- integer- overflow- in-grub_ unicode_ ag.patch patches/ kern-efi- sb-Enforce- verification- of-font- files.patch build-efi- image patches/ font-Try- opening- fonts-from- the-bundled- memdisk. patch patches/ commands- efi-tpm- Refine- the-status- of-log- event.patch patches/ commands- efi-tpm- Use-grub_ strcpy- instead- of-grub_ memcpy. patch patches/ efi-tpm- Add-EFI_ CC_MEASUREMENT_ PROTOCOL- support. patch patches/ ubuntu- fix-reproducibl e-squashfs- test.patch patches/ tests-Explicitl y-unset- SOURCE_ DATE_EPOCH- before- running- f.patch sbat.ubuntu. csv.in grub2-unsigned
- add debian/
- add debian/
- CVE-2022-2601, CVE-2022-3775
- LP: #1996950
* Fix various issues as a result of fuzzing, static analysis and code
review:
- add debian/
- add debian/
- add debian/
- add debian/
- add debian/
- add debian/
- add debian/
- add debian/
- add debian/
- add debian/
* Enforce verification of fonts when secure boot is enabled:
- add debian/
* Bundle unicode.pf2 in a squashfs memdisk attached to the signed EFI binary
- update debian/control
- update debian/
- add debian/
* Fix LP: #1997006 - add support for performing measurements to RTMRs
- add debian/
- add debian/
- add debian/
* Fix the squashfs tests during the build
- remove debian/
- add debian/
* Bump SBAT generation:
- update debian/
* Source package generated from src:grub2 using make -f ./debian/rules
generate-
-- Chris Coulson <email address hidden> Wed, 16 Nov 2022 14:40:42 +0000