By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: GRUB Bootloader Received 73 Patches To Fix A Variety Of Recent Security Issues
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > GRUB Bootloader Received 73 Patches To Fix A Variety Of Recent Security Issues
Computing

GRUB Bootloader Received 73 Patches To Fix A Variety Of Recent Security Issues

News Room
Last updated: 2025/03/24 at 8:47 PM
News Room Published 24 March 2025
Share
SHARE

The GRUB bootloader saw a set of 73 patches last month for addressing a variety of security flaws that were discovered.

Flying under the radar until now was a set of 73 patches needed in February to address a number of security issues, several of which were issued CVEs for the potentially exploitable security woes.

While public one month and the patches were committed to the GRUB Git codebase, no new tagged GRUB version has yet to be published. In fact, no new GRUB releases since the GRUB 2.12 release already 15 months ago.

GRUB2

These GRUB security patches were only raised on my radar today with the GNU Boot 0.1 RC6 release. The new GNU Boot release candidate calls attention to the multiple security issues facing GRUB and thus they updated their included copy of GRUB with the necessary security patches. Among the GRUB security issues potentially impacting the GNU Boot users:

“Users having replaced the GNU Boot picture / logo with untrusted pictures could have been affected if the pictures they used were specially crafted to exploit a vulnerability in GRUB and take full control of the computer. In general it’s a good idea to avoid using untrusted pictures in GRUB or other boot software to limit such risks because software can have bugs (a similar issue also happened in a free software UEFI implementation).

Users having implemented various user-respecting flavor(s) of secure-boot, either by using GPG signatures and/or by using a GRUB password combined with full disk encryption are also affected as these security vulnerabilities could enable people to bypass secure-boot schemes.

In addition there are also security vulnerabilities in file systems, which also enable execution of code. When booting, GRUB has to load files (like the Linux or linux-libre kernel) that are executed anyway. But in some cases, it could still affect users.

This could happen when trying to boot from an USB key, and also having another USB key that has a file system that was crafted to take control of the computer.”

The 73 patches can be found on the GRUB mailing list along with more details on the issues for those interested. The issues range from out-of-bounds writes to integer overflows, the dump command now being in lockdwon mode when using Secure Boot, and other issues.

The only bit of good news is that the “major Linux distros carry or will carry soon oneform or another of these patches” so the likelihood of exploiting these issues at scale is hopefully minimal. Today’s GNU Boot announcement does note that some free software Linux distributions endorsed by the FSF are not comfortable in using GRUB Git snapshots and thus still vulnerable:

“For most 100% free distributions, using GRUB from git would be a significant effort in testing and/or in packaging.

We notified Trisquel, Parabola and Guix and the ones who responded are not comfortable with updating GRUB to a not-yet released git revision. Though in the case of Parabola nothing prevent adding a new grub-git package that has no known vulnerabilities in addition to the existing grub package, so patches for that are welcome.”

Hopefully GRUB will be able to improve their release process as a side effect of these issues.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Amazon Echo Dot and Pop deals: Save as much as 25%
Next Article The best budget robot vacuums
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Chase Bank Is Now Blocking Some Zelle Charges. Here's How You Can Send Money Instead
News
RSAC 2025: Key cybersecurity insights from theCUBE – News
News
Netflix Removes Its Last Interactive Specials, Including This Fan Favorite
News
Shrink your smartphone down to the size of a credit card for under $100
News

You Might also Like

Computing

GSoC 2025 Projects: AI-Powered Log Analyzer For Fedora, Better AMD ROCm On Debian

4 Min Read
Computing

The Linux Kernel Dropping Its Unused Built-In Software Echo Cancellation Code

2 Min Read
Computing

Intel oneDNN 3.8 Brings More CPU & GPU Performance Optimizations

3 Min Read
Computing

Nvidia’s tailored-for-China H20 AI chip now available for pre-orders · TechNode

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?