mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-19 16:40:46 -09:00
boot/grub2: bump to version 2.12
For release announce on mailing list, see [1].
For release general news, see [2].
This commit removes all package patches, as they are all included in
this version.
The .checkpackageignore file is updated accordingly (the entry for
patch 0001 is removed).
This commit also removes GRUB2_AVOID_AUTORECONF hooks, since patch
0001 is removed.
This commit also removes the GRUB2_IGNORE_CVES entries associated to
the removed patches. The version bump should now explicitly exclude
those CVEs. For patches 8 and 9, the upstream commit IDs were
incorrectly recorded:
- patch 8 mentioned d5caac8ab79d068ad9a41030c772d03a4d4fbd7b while
the actual commit is 5bff31cdb6b93d738f850834e6291df1d0b136fa
- patch 9 mentioned 166a4d61448f74745afe1dac2f2cfb85d04909bf while
the actual commit is 347880a13c239b4c2811c94c9a7cf78b607332e3
Finally, this commit introduces a new patch, adding a missing file in
the release tarball.
[1] https://lists.gnu.org/archive/html/grub-devel/2023-12/msg00052.html
[2] https://git.savannah.gnu.org/gitweb/?p=grub.git;a=blob;f=NEWS;hb=refs/tags/grub-2.12
Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
This commit is contained in:
committed by
Yann E. MORIN
parent
fc8eff0c76
commit
5baf1ffe7e
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
GRUB2_VERSION = 2.06
|
||||
GRUB2_VERSION = 2.12
|
||||
GRUB2_SITE = http://ftp.gnu.org/gnu/grub
|
||||
GRUB2_SOURCE = grub-$(GRUB2_VERSION).tar.xz
|
||||
GRUB2_LICENSE = GPL-3.0+
|
||||
@@ -13,13 +13,6 @@ GRUB2_DEPENDENCIES = host-bison host-flex host-grub2
|
||||
HOST_GRUB2_DEPENDENCIES = host-bison host-flex
|
||||
GRUB2_INSTALL_IMAGES = YES
|
||||
|
||||
# 0001-Makefile-Make-grub_fstest.pp-depend-on-config-util.h.patch
|
||||
define GRUB2_AVOID_AUTORECONF
|
||||
$(Q)touch $(@D)/Makefile.in
|
||||
endef
|
||||
GRUB2_POST_PATCH_HOOKS += GRUB2_AVOID_AUTORECONF
|
||||
HOST_GRUB2_POST_PATCH_HOOKS += GRUB2_AVOID_AUTORECONF
|
||||
|
||||
# CVE-2019-14865 is about a flaw in the grub2-set-bootflag tool, which
|
||||
# doesn't exist upstream, but is added by the Redhat/Fedora
|
||||
# packaging. Not applicable to Buildroot.
|
||||
@@ -30,29 +23,8 @@ GRUB2_IGNORE_CVES += CVE-2019-14865
|
||||
# grub_linuxefi_secure_validate() is not implemented in the grub2
|
||||
# version available in Buildroot.
|
||||
GRUB2_IGNORE_CVES += CVE-2020-15705
|
||||
# 0002-grub-mkconfig-Restore-umask-for-the-grub.cfg.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2021-3981
|
||||
# vulnerability is specific to the SUSE distribution
|
||||
GRUB2_IGNORE_CVES += CVE-2021-46705
|
||||
# 0005-loader-efi-chainloader-Use-grub_loader_set_ex.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2022-28736
|
||||
# 0006-kern-efi-sb-Reject-non-kernel-files-in-the-shim_lock.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2022-28735
|
||||
# 0010-video-readers-png-Drop-greyscale-support-to-fix-heap.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2021-3695
|
||||
# 0011-video-readers-png-Avoid-heap-OOB-R-W-inserting-huff-.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2021-3696
|
||||
# 0012-video-readers-jpeg-Block-int-underflow-wild-pointer-.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2021-3697
|
||||
# 0013-net-ip-Do-IP-fragment-maths-safely.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2022-28733
|
||||
# 0014-net-http-Fix-OOB-write-for-split-http-headers.patch
|
||||
# 0015-net-http-Error-out-on-headers-with-LF-without-CR.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2022-28734
|
||||
# 0017-font-Fix-several-integer-overflows-in-grub_font_cons.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2022-2601
|
||||
# 0018-font-Fix-an-integer-underflow-in-blit_comb.patch
|
||||
GRUB2_IGNORE_CVES += CVE-2022-3775
|
||||
|
||||
ifeq ($(BR2_TARGET_GRUB2_INSTALL_TOOLS),y)
|
||||
GRUB2_INSTALL_TARGET = YES
|
||||
|
||||
Reference in New Issue
Block a user