Bug#1144079: Mismerge of CVE-2025-13151

Bastien Roucaries <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <2142111.0S5aU1g85B__39439.3652839185$1786391598$gmane$org@debian-ei>
Source: grub2
Severity: serious
Tags: security
Justification: security
X-Debbugs-Cc: Debian Security Team <[email protected]>
X-Debbugs-Cc: Gajendra Nath Soren <[email protected]>

CVE-2025-13151 (libtasn1 - off-by-one in asn1_expand_octet_string, fixed in
4.20.0)

The fix changes:
  char name[2 * ASN1_MAX_NAME_SIZE + 1]

 to:
   char name[2 * ASN1_MAX_NAME_SIZE + 2]

This applies to two functions: asn1_expand_any_defined_by and
asn1_expand_octet_string.

Grub2 vendor libtasn1 internally and show a partial fix -
asn1_expand_any_defined_by has been updated (+ 2 present) but
asn1_expand_octet_string still carries the vulnerable version (+ 1):
   - grub2 (grub-core/lib/libtasn1/lib/decoding.c)
        asn1_expand_any_defined_by: patched
     asn1_expand_octet_string: VULNERABLE
     Note: grub2 carries two separate embedded copies (libtasn1 and
 libtasn1-grub)

Thanks to Gajendra Nath Soren 

rouca
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmp6K4cACgkQADoaLapB
CF/4KBAAkiQuVMTQUJidj4OPYCjAcQP8RzM19/A6pwed1ZnIpgk7EFUgoHqJVtsG
Ch5NCHVh5TkK2XsDUZnLkMKHO/La/h2FLcBs0grnMtoH1BMgIYEu50KiKn9GFFqT
cFhV3juSyPBx5gVNM9GXwv3uGxHYZNfn+4XPfd1sy4ZWkqVWWk8jLxKSi8i9oIkC
sRIceB3I8dx7DY7BP9Ck4VWMFhMHTEMoaYWKqs/l0/JTZTbelV3+u6GgQTufPvDf
nBJslaCBfj5DnPK/VeDHzZqCp+X901Rbh2H92KcdqfrjtGHl6gcmMbzftnKxn88Y
mnxaDUvfZMscPZaPJ1g7/B3QFk+B9qLkYv0UdnHz5hwoChsZSRLqxVIRjMuaodT2
CDXC2toR2ylEk2dG3FMxwxJO559bxDSscsTIBvAOxHX9RpsB7Ne/GESR1SIhl9Ms
dHXTFKHI5oNXSInUodVvdzVa+6FzObA0fjiH+IBEN4MHTbmX4cvuvBuYAbkZhD9T
3pcfaATAEwViCghWAD/I9cfvBmv9DVFHmkwWrRSJ6vUrGuQhXrU74gfvXk7XNYT/
tcQSgo+JFJQUC15iyqBdlX6Oj8PA+2h5FTn+j9+vNVP9WV20sme1y/Z5wz0Lw+f2
afs/aOWYGLQZGtal3+C9dcZUKU09IAv5mww86MvT0Ky8U9h4sYc=
=xVCp
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.