安全公告详情

NS-SA-2026-0058

2026-07-27 21:21:35

简介

important: grub2/glibc security update

严重级别

important

主题

An update for grub2/glibc is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

grub2:
glibc:


Security Fix(es):
grub2: A flaw was found in the grub2 font code. When rendering certain unicode sequences, it fails to properly validate the font width and height. These values are further used to access the font buffer, causing possible out-of-bounds writes. A malicious actor may craft a font capable of triggering this issue, allowing modifications in unauthorized memory segments, causing data integrity problems or leading to denial of service.(CVE-2022-3775)
grub2: bugfix
glibc: An out-of-bounds write flaw was found in the ISO-2022-CN-EXT plugin for glibc's iconv library. When converting from UCS4 charset, adding certain escape charterers is required to indicate where the charset was changed to the library. During this process, iconv improperly checks the boundaries of internal buffers, leading to a buffer overflow, which allows writing up to 3 bytes outside the desired memory location. This issue may allow an attacker to craft a malicious characters sequence that will trigger the out-of-bounds write and perform remote code execution, presenting a high impact to the Integrity, Confidentiality, and Availability triad.(CVE-2024-2961)
glibc: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.11B10.

影响组件

  • grub2
  • glibc

影响产品

  • CGSL MAIN 6.06

更新包

{"fix":[{"product":"CGSL MAIN 6.06","pkgs":[{"binary":["grub2-common-2.02-123.0.2.zncgsl6_6.8.t7.0.noarch.rpm","grub2-efi-x64-modules-2.02-123.0.2.zncgsl6_6.8.t7.0.noarch.rpm","grub2-efi-x64-2.02-123.0.2.zncgsl6_6.8.t7.0.x86_64.rpm","grub2-pc-2.02-123.0.2.zncgsl6_6.8.t7.0.x86_64.rpm","grub2-pc-modules-2.02-123.0.2.zncgsl6_6.8.t7.0.noarch.rpm","grub2-tools-efi-2.02-123.0.2.zncgsl6_6.8.t7.0.x86_64.rpm","grub2-tools-2.02-123.0.2.zncgsl6_6.8.t7.0.x86_64.rpm","grub2-tools-extra-2.02-123.0.2.zncgsl6_6.8.t7.0.x86_64.rpm","grub2-tools-minimal-2.02-123.0.2.zncgsl6_6.8.t7.0.x86_64.rpm"],"source":"grub2-2.02-123.0.2.zncgsl6_6.8.t7.0.src.rpm"},{"binary":["nss_db-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","compat-libpthread-nonshared-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","libnsl-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-common-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-devel-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-gconv-extra-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-langpack-en-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-headers-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-locale-source-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-langpack-zh-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-minimal-langpack-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-static-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm","glibc-all-langpacks-2.28-225.0.4.zncgsl6.t10.0.x86_64.rpm"],"source":"glibc-2.28-225.0.4.zncgsl6.t10.0.src.rpm"}]}]}

CVE

参考