Bug#1144079: Mismerge of CVE-2025-13151

Carlos Henrique Lima Melara charles at debian.org
Tue Aug 11 05:19:06 BST 2026


Control: found -1 2.14~git20250718.0e36779-1

Hi,

On Mon, Aug 10, 2026 at 09:50:59PM +0200, Bastien Roucaries wrote:
> 
> CVE-2025-13151 (libtasn1 - off-by-one in asn1_expand_octet_string, fixed in
> 4.20.0)
> 
> The fix changes:
>   char name[2 * ASN1_MAX_NAME_SIZE + 1]
> 
>  to:
>    char name[2 * ASN1_MAX_NAME_SIZE + 2]
> 
> This applies to two functions: asn1_expand_any_defined_by and
> asn1_expand_octet_string.
> 
> Grub2 vendor libtasn1 internally and show a partial fix -
> asn1_expand_any_defined_by has been updated (+ 2 present) but
> asn1_expand_octet_string still carries the vulnerable version (+ 1):
>    - grub2 (grub-core/lib/libtasn1/lib/decoding.c)
>         asn1_expand_any_defined_by: patched
>      asn1_expand_octet_string: VULNERABLE
>      Note: grub2 carries two separate embedded copies (libtasn1 and
>  libtasn1-grub)
> 
> Thanks to Gajendra Nath Soren 

This embedded copy was added in 9a26abbc368 (grub-2.14-rc1), so it only
(possibly) affects forky/sid.

Cheers,
Charles



More information about the Pkg-grub-devel mailing list