#991691 Possible CVE-2014-5461 in grub2

Package:
grub2
Source:
grub2
Description:
GRand Unified Bootloader, version 2 (dummy package)
Submitter:
Movses Tovmasyan
Date:
2021-07-30 11:27:02 UTC
Severity:
normal
Tags:
#991691#5
Date:
2021-07-30 10:35:58 UTC
From:
To:
grub2 uses the obsolete version of minilua
(single-file port of Lua) which has CVE-2014-5461
Patch attached below.

#991691#14
Date:
2021-07-30 11:25:18 UTC
From:
To:
Control: tag -1 upstream

The upstream repository for this is
https://git.savannah.gnu.org/cgit/grub-extras.git, and this doesn't seem
to be fixed there.  Could you please send a patch to grub-devel@gnu.org
for review (as a proper textual git patch, not a screenshot of a patch)?
We can then cherry-pick it from there.

I've merged the various bugs that you filed against different versions
and binary packages of the Debian grub2 source package.  We only need
one bug report for this.

Thanks,