Addressed multiple grub2 CVEs #14018
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-static
subpackages, etc.) have had theirRelease
tag incremented../cgmanifest.json
,./toolkit/scripts/toolchain/cgmanifest.json
,.github/workflows/cgmanifest.json
)./LICENSES-AND-NOTICES/SPECS/data/licenses.json
,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON
)*.signatures.json
filessudo make go-tidy-all
andsudo make go-test-coverage
passSummary
Addressing Grub2 multiple CVEs
Change Log
Addressed multiple grub2 CVEs
Modified grub2 spec for the same
CVE-2025-0684
CVE-2024-45782
CVE-2024-45778
CVE-2025-0686
CVE-2025-0678
CVE-2025-0685
CVE-2024-45779
CVE-2025-0689
CVE-2024-45780
CVE-2025-1125
CVE-2025-0690
CVE-2024-45783
CVE-2024-45776
CVE-2024-45777
CVE-2025-0677
CVE-2025-1118
CVE-2024-45775
CVE-2024-45781
CVE-2024-45774
CVE-2024-56737
CVE-2017-7526
CVE-2019-13627
CVE-2014-3591
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology