摘要:
grub2 security update
安全等级: Critical
公告ID: KylinSec-SA-2024-4782
发布日期: 2025年2月17日
关联CVE: CVE-2021-46848
GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn.
Security Fix(es):
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.(CVE-2021-46848)
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2021-46848 | V6 | libtasn1 | Fixed |
软件名称 | 架构 | 版本号 |
---|---|---|
grub2-efi-aa64-modules | noarch | 2.12-33.ks6 |
grub2-help | noarch | 2.12-25.ks6.kb6 |
grub2-efi-x64-modules | noarch | 2.12-25.ks6.kb6 |
grub2-efi-ia32-modules | noarch | 2.12-25.ks6.kb6 |
grub2-common | noarch | 2.12-25.ks6.kb6 |
grub2-pc-modules | noarch | 2.12-25.ks6.kb6 |
grub2-tools-extra | x86_64 | 2.12-25.ks6.kb6 |
grub2-pc | x86_64 | 2.12-25.ks6.kb6 |
grub2-tools-minimal | x86_64 | 2.12-25.ks6.kb6 |
grub2-tools-efi | x86_64 | 2.12-25.ks6.kb6 |
grub2-efi-ia32 | x86_64 | 2.12-25.ks6.kb6 |
grub2-efi-ia32-cdboot | x86_64 | 2.12-25.ks6.kb6 |
grub2-efi-x64 | x86_64 | 2.12-25.ks6.kb6 |
grub2-tools | x86_64 | 2.12-25.ks6.kb6 |
grub2-efi-x64-cdboot | x86_64 | 2.12-25.ks6.kb6 |
grub2-efi-aa64 | aarch64 | 2.12-33.ks6 |
grub2-efi-aa64-cdboot | aarch64 | 2.12-33.ks6 |
grub2-tools-minimal | aarch64 | 2.12-33.ks6 |
grub2-tools-extra | aarch64 | 2.12-33.ks6 |
grub2-tools | aarch64 | 2.12-33.ks6 |
方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm
方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名