Bug#1144079: Mismerge of CVE-2025-13151

Bastien Roucaries <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <1957669.R1toDxpfAE@debian-ei>
Le mardi 11 août 2026, 06:19:06 heure d’été d’Europe centrale Carlos Henrique Lima Melara a écrit :
> Control: found -1 2.14~git20250718.0e36779-1
> 
> Hi,
> 
> On Mon, Aug 10, 2026 at 09:50:59PM +0200, Bastien Roucaries wrote:
> > 
> > CVE-2025-13151 (libtasn1 - off-by-one in asn1_expand_octet_string, fixed in
> > 4.20.0)
> > 
> > The fix changes:
> >   char name[2 * ASN1_MAX_NAME_SIZE + 1]
> > 
> >  to:
> >    char name[2 * ASN1_MAX_NAME_SIZE + 2]
> > 
> > This applies to two functions: asn1_expand_any_defined_by and
> > asn1_expand_octet_string.
> > 
> > Grub2 vendor libtasn1 internally and show a partial fix -
> > asn1_expand_any_defined_by has been updated (+ 2 present) but
> > asn1_expand_octet_string still carries the vulnerable version (+ 1):
> >    - grub2 (grub-core/lib/libtasn1/lib/decoding.c)
> >         asn1_expand_any_defined_by: patched
> >      asn1_expand_octet_string: VULNERABLE
> >      Note: grub2 carries two separate embedded copies (libtasn1 and
> >  libtasn1-grub)
> > 
> > Thanks to Gajendra Nath Soren 
> 
> This embedded copy was added in 9a26abbc368 (grub-2.14-rc1), so it only
> (possibly) affects forky/sid.

Can we report upstream ? 

rouca
> 
> Cheers,
> Charles
>
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmp62x4ACgkQADoaLapB
CF/I1Q//bdnhH5ATs70pRAlINvNFiiCe8Qt/AmL0Tppu+zifEwH2s/x96jZB+Bn5
rj+4mTA+T9EYrU0iU7p6b7BMzMyFwA0gaw3Le4G9HbngzMMKfEN+WJSFegmTOphA
EoDh1YdA/2rNxQ8w11wVW3rXaLeqJgWzf4E805HGDbrkfj6nqKmMINdgqlHGK7q4
WjEbirjuZAocC6xZFX5HJL3Om6IWKZilIuTvertOjCq/ut21l5nBl+cHq+qXy/vC
scKeXI3az7utjW6j21YwoOsOf0JFrfPJtsyRRm2ve6ovn58Z6LzIqtAmLYR/qFLs
7IH4ttIH5qbMNqIFHPrkyMII6WY8MKizrT2qZaSa0+N5w7qKq+ML93SkVOC/Cktr
ttJs07TpCGuKdwr+Xd4n0XW2O1A0uu8LXMOq9h+rZYlLqVKccvYKqW5N1A9JNnC7
YzcMDgsJ2MhhqSlwuqJUBX1Bcf0zmSHRCeaGkxJjQl/qMb/N3/rx0N/Iuo+3N0Pj
2gEm7x9qTxtW1nR0LNgQpxMuiFWJtGZpsljma3WOdb4o59T3Yf2hQEi6IdEKgf8M
9kD794lGg+Aqu7ltyyM2z606w+QKt1f4ngOt3E2ycq/wonDwBESrvwEwRocLv7v3
F2inQnXdGr+u4+LUAIBsFASpsp4dYpIDBZDbhllFDx+eDY4V+rs=
=oz8i
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.