* Re: Bug#1144079: Mismerge of CVE-2025-13151 [not found] ` <1957669.R1toDxpfAE@debian-ei> @ 2026-08-11 16:26 ` Steve McIntyre 2026-08-11 20:55 ` Mike Gilbert 0 siblings, 1 reply; 3+ messages in thread From: Steve McIntyre @ 2026-08-11 16:26 UTC (permalink / raw) To: Bastien Roucaries, 1144079 Cc: Carlos Henrique Lima Melara, Debian Security Team, Gajendra Nath Soren, grub-devel Adding the GRUB upstream development list on this too; the information is already public in the Debian BTS so there's no point trying to keep thie embargoed. On Tue, Aug 11, 2026 at 10:20:10AM +0200, Bastien Roucaries wrote: >Le mardi 11 août 2026, 06:19:06 heure d’été d’Europe centrale Carlos Henrique Lima Melara a écrit : >> Control: found -1 2.14~git20250718.0e36779-1 >> >> Hi, >> >> On Mon, Aug 10, 2026 at 09:50:59PM +0200, Bastien Roucaries wrote: >> > >> > CVE-2025-13151 (libtasn1 - off-by-one in asn1_expand_octet_string, fixed in >> > 4.20.0) >> > >> > The fix changes: >> > char name[2 * ASN1_MAX_NAME_SIZE + 1] >> > >> > to: >> > char name[2 * ASN1_MAX_NAME_SIZE + 2] >> > >> > This applies to two functions: asn1_expand_any_defined_by and >> > asn1_expand_octet_string. >> > >> > Grub2 vendor libtasn1 internally and show a partial fix - >> > asn1_expand_any_defined_by has been updated (+ 2 present) but >> > asn1_expand_octet_string still carries the vulnerable version (+ 1): >> > - grub2 (grub-core/lib/libtasn1/lib/decoding.c) >> > asn1_expand_any_defined_by: patched >> > asn1_expand_octet_string: VULNERABLE >> > Note: grub2 carries two separate embedded copies (libtasn1 and >> > libtasn1-grub) >> > >> > Thanks to Gajendra Nath Soren >> >> This embedded copy was added in 9a26abbc368 (grub-2.14-rc1), so it only >> (possibly) affects forky/sid. > >Can we report upstream ? > >rouca >> >> Cheers, >> Charles >> > -- Steve McIntyre, Cambridge, UK. steve@einval.com Armed with "Valor": "Centurion" represents quality of Discipline, Honor, Integrity and Loyalty. Now you don't have to be a Caesar to concord the digital world while feeling safe and proud. _______________________________________________ Grub-devel mailing list Grub-devel@gnu.org https://lists.gnu.org/mailman/listinfo/grub-devel ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Bug#1144079: Mismerge of CVE-2025-13151 2026-08-11 16:26 ` Bug#1144079: Mismerge of CVE-2025-13151 Steve McIntyre @ 2026-08-11 20:55 ` Mike Gilbert 2026-08-11 21:12 ` Leo Sandoval via Grub-devel 0 siblings, 1 reply; 3+ messages in thread From: Mike Gilbert @ 2026-08-11 20:55 UTC (permalink / raw) To: The development of GNU GRUB Cc: Bastien Roucaries, 1144079, Carlos Henrique Lima Melara, Debian Security Team, Gajendra Nath Soren On Tue, Aug 11, 2026 at 12:26 PM Steve McIntyre <steve@einval.com> wrote: > > Adding the GRUB upstream development list on this too; the information > is already public in the Debian BTS so there's no point trying to keep > thie embargoed. > > On Tue, Aug 11, 2026 at 10:20:10AM +0200, Bastien Roucaries wrote: > >Le mardi 11 août 2026, 06:19:06 heure d’été d’Europe centrale Carlos Henrique Lima Melara a écrit : > >> Control: found -1 2.14~git20250718.0e36779-1 > >> > >> Hi, > >> > >> On Mon, Aug 10, 2026 at 09:50:59PM +0200, Bastien Roucaries wrote: > >> > > >> > CVE-2025-13151 (libtasn1 - off-by-one in asn1_expand_octet_string, fixed in > >> > 4.20.0) > >> > > >> > The fix changes: > >> > char name[2 * ASN1_MAX_NAME_SIZE + 1] > >> > > >> > to: > >> > char name[2 * ASN1_MAX_NAME_SIZE + 2] > >> > > >> > This applies to two functions: asn1_expand_any_defined_by and > >> > asn1_expand_octet_string. > >> > > >> > Grub2 vendor libtasn1 internally and show a partial fix - > >> > asn1_expand_any_defined_by has been updated (+ 2 present) but > >> > asn1_expand_octet_string still carries the vulnerable version (+ 1): > >> > - grub2 (grub-core/lib/libtasn1/lib/decoding.c) > >> > asn1_expand_any_defined_by: patched > >> > asn1_expand_octet_string: VULNERABLE > >> > Note: grub2 carries two separate embedded copies (libtasn1 and > >> > libtasn1-grub) > >> > > >> > Thanks to Gajendra Nath Soren > >> > >> This embedded copy was added in 9a26abbc368 (grub-2.14-rc1), so it only > >> (possibly) affects forky/sid. > > > >Can we report upstream ? > > > >rouca > >> > >> Cheers, > >> Charles > >> > > Thanks for the heads-up. I created a task on the new GRUB issue tracker. https://gitlab.freedesktop.org/gnu-grub/grub/-/work_items/66 _______________________________________________ Grub-devel mailing list Grub-devel@gnu.org https://lists.gnu.org/mailman/listinfo/grub-devel ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Bug#1144079: Mismerge of CVE-2025-13151 2026-08-11 20:55 ` Mike Gilbert @ 2026-08-11 21:12 ` Leo Sandoval via Grub-devel 0 siblings, 0 replies; 3+ messages in thread From: Leo Sandoval via Grub-devel @ 2026-08-11 21:12 UTC (permalink / raw) To: The development of GNU GRUB Cc: Leo Sandoval, Bastien Roucaries, 1144079, Carlos Henrique Lima Melara, Debian Security Team, Gajendra Nath Soren, tagrain [-- Attachment #1.1: Type: text/plain, Size: 2393 bytes --] + Thomas Grainger Thanks Mike for reporting it. In resume, there is a MR which would solve this https://gitlab.freedesktop.org/gnu-grub/grub/-/merge_requests/177 Thomas, correct me if I am wrong? On Tue, Aug 11, 2026 at 2:56 PM Mike Gilbert <floppym@gentoo.org> wrote: > On Tue, Aug 11, 2026 at 12:26 PM Steve McIntyre <steve@einval.com> wrote: > > > > Adding the GRUB upstream development list on this too; the information > > is already public in the Debian BTS so there's no point trying to keep > > thie embargoed. > > > > On Tue, Aug 11, 2026 at 10:20:10AM +0200, Bastien Roucaries wrote: > > >Le mardi 11 août 2026, 06:19:06 heure d’été d’Europe centrale Carlos > Henrique Lima Melara a écrit : > > >> Control: found -1 2.14~git20250718.0e36779-1 > > >> > > >> Hi, > > >> > > >> On Mon, Aug 10, 2026 at 09:50:59PM +0200, Bastien Roucaries wrote: > > >> > > > >> > CVE-2025-13151 (libtasn1 - off-by-one in asn1_expand_octet_string, > fixed in > > >> > 4.20.0) > > >> > > > >> > The fix changes: > > >> > char name[2 * ASN1_MAX_NAME_SIZE + 1] > > >> > > > >> > to: > > >> > char name[2 * ASN1_MAX_NAME_SIZE + 2] > > >> > > > >> > This applies to two functions: asn1_expand_any_defined_by and > > >> > asn1_expand_octet_string. > > >> > > > >> > Grub2 vendor libtasn1 internally and show a partial fix - > > >> > asn1_expand_any_defined_by has been updated (+ 2 present) but > > >> > asn1_expand_octet_string still carries the vulnerable version (+ 1): > > >> > - grub2 (grub-core/lib/libtasn1/lib/decoding.c) > > >> > asn1_expand_any_defined_by: patched > > >> > asn1_expand_octet_string: VULNERABLE > > >> > Note: grub2 carries two separate embedded copies (libtasn1 and > > >> > libtasn1-grub) > > >> > > > >> > Thanks to Gajendra Nath Soren > > >> > > >> This embedded copy was added in 9a26abbc368 (grub-2.14-rc1), so it > only > > >> (possibly) affects forky/sid. > > > > > >Can we report upstream ? > > > > > >rouca > > >> > > >> Cheers, > > >> Charles > > >> > > > > > Thanks for the heads-up. I created a task on the new GRUB issue tracker. > > https://gitlab.freedesktop.org/gnu-grub/grub/-/work_items/66 > > _______________________________________________ > Grub-devel mailing list > Grub-devel@gnu.org > https://lists.gnu.org/mailman/listinfo/grub-devel > > [-- Attachment #1.2: Type: text/html, Size: 3742 bytes --] [-- Attachment #2: Type: text/plain, Size: 141 bytes --] _______________________________________________ Grub-devel mailing list Grub-devel@gnu.org https://lists.gnu.org/mailman/listinfo/grub-devel ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-11 21:13 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <anqhaAq4ITWnZGRH@fw13.lan>
[not found] ` <2142111.0S5aU1g85B@debian-ei>
[not found] ` <1957669.R1toDxpfAE@debian-ei>
2026-08-11 16:26 ` Bug#1144079: Mismerge of CVE-2025-13151 Steve McIntyre
2026-08-11 20:55 ` Mike Gilbert
2026-08-11 21:12 ` Leo Sandoval via Grub-devel
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.