ELA-1783-1 grub2 security update

SecureBoot bypass

2026-07-24
Packagegrub2
Version2.06-3~deb10u5 (buster)
Related CVEs CVE-2024-45774 CVE-2024-45775 CVE-2024-45776 CVE-2024-45777 CVE-2024-45778 CVE-2024-45779 CVE-2024-45780 CVE-2024-45781 CVE-2024-45782 CVE-2024-45783 CVE-2025-0622 CVE-2025-0624 CVE-2025-0677 CVE-2025-0678 CVE-2025-0684 CVE-2025-0685 CVE-2025-0686 CVE-2025-0689 CVE-2025-0690 CVE-2025-1118 CVE-2025-1125


Several issues were found in the GRUB2 bootloader, which could result in crashes and potentially execution of arbitrary code. These could lead to bypass of UEFI Secure Boot on affected systems.



For Debian 10 buster, these problems have been fixed in version 2.06-3~deb10u5.

We recommend that you upgrade your grub2 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.