[Git][security-tracker-team/security-tracker][master] lts: mark some grub2 issues as postponed for bullseye

Emilio Pozuelo Monfort (@pochu) pochu at debian.org
Wed Jul 15 12:24:44 BST 2026



Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
675360c0 by Emilio Pozuelo Monfort at 2026-07-15T13:24:19+02:00
lts: mark some grub2 issues as postponed for bullseye

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -128975,21 +128975,25 @@ CVE-2025-61664 (A vulnerability in the GRUB2 bootloader has been identified in t
 	- grub2 2.14-1 (bug #1120968)
 	[trixie] - grub2 <no-dsa> (Minor issue)
 	[bookworm] - grub2 <no-dsa> (Minor issue)
+	[bullseye] - grub2 <postponed> (Minor issue)
 	NOTE: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=05d3698b8b03eccc49e53491bbd75dba15f40917 (grub-2.14)
 CVE-2025-61663 (A vulnerability has been identified in the GRUB2 bootloader's normal c ...)
 	- grub2 2.14-1 (bug #1120968)
 	[trixie] - grub2 <no-dsa> (Minor issue)
 	[bookworm] - grub2 <no-dsa> (Minor issue)
+	[bullseye] - grub2 <postponed> (Minor issue)
 	NOTE: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=05d3698b8b03eccc49e53491bbd75dba15f40917 (grub-2.14)
 CVE-2025-61662 (A Use-After-Free vulnerability has been discovered in GRUB's gettext m ...)
 	- grub2 2.14-1 (bug #1120968)
 	[trixie] - grub2 <no-dsa> (Minor issue)
 	[bookworm] - grub2 <no-dsa> (Minor issue)
+	[bullseye] - grub2 <postponed> (Minor issue)
 	NOTE: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=8ed78fd9f0852ab218cc1f991c38e5a229e43807 (grub-2.14)
 CVE-2025-61661 (A vulnerability has been identified in the GRUB (Grand Unified Bootloa ...)
 	- grub2 2.14-1 (bug #1120968)
 	[trixie] - grub2 <no-dsa> (Minor issue)
 	[bookworm] - grub2 <no-dsa> (Minor issue)
+	[bullseye] - grub2 <postponed> (Minor issue)
 	NOTE: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=549a9cc372fd0b96a4ccdfad0e12140476cc62a3 (grub-2.14)
 CVE-2025-60455 (Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, ...)
 	NOT-FOR-US: Modular Max Serve
@@ -129045,11 +129049,13 @@ CVE-2025-54771 (A use-after-free vulnerability has been identified in the GNU GR
 	- grub2 2.14-1 (bug #1120968)
 	[trixie] - grub2 <no-dsa> (Minor issue)
 	[bookworm] - grub2 <no-dsa> (Minor issue)
+	[bullseye] - grub2 <postponed> (Minor issue)
 	NOTE: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=c4fb4cbc941981894a00ba8e75d634a41967a27f (grub-2.14)
 CVE-2025-54770 (A vulnerability has been identified in the GRUB2 bootloader's network  ...)
 	- grub2 2.14-1 (bug #1120968)
 	[trixie] - grub2 <no-dsa> (Minor issue)
 	[bookworm] - grub2 <no-dsa> (Minor issue)
+	[bullseye] - grub2 <postponed> (Minor issue)
 	NOTE: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=10e58a14db20e17d1b6a39abe38df01fef98e29d (grub-2.14)
 CVE-2025-54660 (An active debug code vulnerability in Fortinet FortiClientWindows 7.4. ...)
 	NOT-FOR-US: Fortinet
@@ -192162,6 +192168,7 @@ CVE-2025-4382 (A flaw was found in systems utilizing LUKS-encrypted disks with G
 	- grub2 2.14~git20250718.0e36779-2 (bug #1105108)
 	[trixie] - grub2 <no-dsa> (Minor issue)
 	[bookworm] - grub2 <no-dsa> (Minor issue)
+	[bullseye] - grub2 <postponed> (Minor issue)
 	NOTE: Fixed by: https://git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=c448f511e74cb7c776b314fcb7943f98d3f22b6d (grub-2.14-rc1)
 	NOTE: Additional hardening via:
 	NOTE: https://git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=ed691c0e0e20d9d0e8d8305a120e8c61d6be3d38
@@ -236661,10 +236668,12 @@ CVE-2024-56738 (GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time a
 	- grub2 <unfixed> (bug #1102217)
 	[trixie] - grub2 <postponed> (Minor issue, revisit when fixed upstream)
 	[bookworm] - grub2 <postponed> (Minor issue, revisit when fixed upstream)
+	[bullseye] - grub2 <postponed> (Minor issue)
 	NOTE: https://savannah.gnu.org/bugs/?66603
 CVE-2024-56737 (GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in  ...)
 	- grub2 2.12-6
 	[bookworm] - grub2 <no-dsa> (Minor issue)
+	[bullseye] - grub2 <postponed> (Minor issue)
 	NOTE: https://savannah.gnu.org/bugs/?66599
 CVE-2024-13006 (A vulnerability, which was classified as critical, has been found in 1 ...)
 	NOT-FOR-US: 1000 Projects Human Resource Management System



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/675360c0f729027c000274757f3b614e6b7e185f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/675360c0f729027c000274757f3b614e6b7e185f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260715/e1f2ec19/attachment.htm>


More information about the debian-security-tracker-commits mailing list