<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for grub2</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2025:01615-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2025-05-21T09:53:07Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-05-21T09:53:07Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-05-21T09:53:07Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for grub2</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update for grub2 rebuilds the existing package with the new 4k RSA secure boot key for IBM Power and Z.

Note: the signing key of x86 / x86_64 and aarch64 architectures are unchanged.

Also the following issue were fixed:

- CVE-2025-4382: TPM auto-decryption data exposure (bsc#1242971)
- Fix segmentation fault error in grub2-probe with target=hints_string (bsc#1235971) (bsc#1235958) (bsc#1239651)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2025-1615,SUSE-SLE-Module-Basesystem-15-SP6-2025-1615,SUSE-SLE-Module-Server-Applications-15-SP6-2025-1615,openSUSE-SLE-15.6-2025-1615</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202501615-1/</URL>
      <Description>Link for SUSE-SU-2025:01615-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2025-May/039291.html</URL>
      <Description>E-Mail link for SUSE-SU-2025:01615-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1235958</URL>
      <Description>SUSE Bug 1235958</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1235971</URL>
      <Description>SUSE Bug 1235971</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1239651</URL>
      <Description>SUSE Bug 1239651</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1242971</URL>
      <Description>SUSE Bug 1242971</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-4382/</URL>
      <Description>SUSE CVE CVE-2025-4382 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Basesystem 15 SP6">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP6">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6" CPE="cpe:/o:suse:sle-module-basesystem:15:sp6">SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Server Applications 15 SP6">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6" CPE="cpe:/o:suse:sle-module-server-applications:15:sp6">SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.6">
      <Branch Type="Product Name" Name="openSUSE Leap 15.6">
        <FullProductName ProductID="openSUSE Leap 15.6" CPE="cpe:/o:opensuse:leap:15.6">openSUSE Leap 15.6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="grub2-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-2.12-150600.8.27.1">grub2-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-arm64-efi-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-arm64-efi-2.12-150600.8.27.1">grub2-arm64-efi-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-i386-pc-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-i386-pc-2.12-150600.8.27.1">grub2-i386-pc-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-powerpc-ieee1275-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-powerpc-ieee1275-2.12-150600.8.27.1">grub2-powerpc-ieee1275-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-s390x-emu-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-s390x-emu-2.12-150600.8.27.1">grub2-s390x-emu-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-snapper-plugin-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-snapper-plugin-2.12-150600.8.27.1">grub2-snapper-plugin-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-systemd-sleep-plugin-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-systemd-sleep-plugin-2.12-150600.8.27.1">grub2-systemd-sleep-plugin-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-x86_64-efi-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-x86_64-efi-2.12-150600.8.27.1">grub2-x86_64-efi-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-x86_64-xen-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-x86_64-xen-2.12-150600.8.27.1">grub2-x86_64-xen-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-arm64-efi-debug-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-arm64-efi-debug-2.12-150600.8.27.1">grub2-arm64-efi-debug-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-arm64-efi-extras-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-arm64-efi-extras-2.12-150600.8.27.1">grub2-arm64-efi-extras-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-branding-upstream-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-branding-upstream-2.12-150600.8.27.1">grub2-branding-upstream-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-i386-pc-debug-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-i386-pc-debug-2.12-150600.8.27.1">grub2-i386-pc-debug-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-i386-pc-extras-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-i386-pc-extras-2.12-150600.8.27.1">grub2-i386-pc-extras-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-i386-xen-debug-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-i386-xen-debug-2.12-150600.8.27.1">grub2-i386-xen-debug-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-powerpc-ieee1275-debug-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-powerpc-ieee1275-debug-2.12-150600.8.27.1">grub2-powerpc-ieee1275-debug-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-powerpc-ieee1275-extras-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-powerpc-ieee1275-extras-2.12-150600.8.27.1">grub2-powerpc-ieee1275-extras-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-s390x-emu-debug-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-s390x-emu-debug-2.12-150600.8.27.1">grub2-s390x-emu-debug-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-s390x-emu-extras-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-s390x-emu-extras-2.12-150600.8.27.1">grub2-s390x-emu-extras-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-x86_64-efi-debug-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-x86_64-efi-debug-2.12-150600.8.27.1">grub2-x86_64-efi-debug-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-x86_64-efi-extras-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-x86_64-efi-extras-2.12-150600.8.27.1">grub2-x86_64-efi-extras-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-x86_64-xen-debug-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-x86_64-xen-debug-2.12-150600.8.27.1">grub2-x86_64-xen-debug-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="grub2-x86_64-xen-extras-2.12-150600.8.27.1">
      <FullProductName ProductID="grub2-x86_64-xen-extras-2.12-150600.8.27.1">grub2-x86_64-xen-extras-2.12-150600.8.27.1</FullProductName>
    </Branch>
    <Relationship ProductReference="grub2-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-2.12-150600.8.27.1">grub2-2.12-150600.8.27.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-arm64-efi-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-arm64-efi-2.12-150600.8.27.1">grub2-arm64-efi-2.12-150600.8.27.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-i386-pc-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-i386-pc-2.12-150600.8.27.1">grub2-i386-pc-2.12-150600.8.27.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-powerpc-ieee1275-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-powerpc-ieee1275-2.12-150600.8.27.1">grub2-powerpc-ieee1275-2.12-150600.8.27.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-s390x-emu-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-s390x-emu-2.12-150600.8.27.1">grub2-s390x-emu-2.12-150600.8.27.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-snapper-plugin-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-snapper-plugin-2.12-150600.8.27.1">grub2-snapper-plugin-2.12-150600.8.27.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-systemd-sleep-plugin-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-systemd-sleep-plugin-2.12-150600.8.27.1">grub2-systemd-sleep-plugin-2.12-150600.8.27.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-x86_64-efi-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-x86_64-efi-2.12-150600.8.27.1">grub2-x86_64-efi-2.12-150600.8.27.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-x86_64-xen-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:grub2-x86_64-xen-2.12-150600.8.27.1">grub2-x86_64-xen-2.12-150600.8.27.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-2.12-150600.8.27.1">grub2-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-arm64-efi-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-arm64-efi-2.12-150600.8.27.1">grub2-arm64-efi-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-arm64-efi-debug-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-arm64-efi-debug-2.12-150600.8.27.1">grub2-arm64-efi-debug-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-arm64-efi-extras-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-arm64-efi-extras-2.12-150600.8.27.1">grub2-arm64-efi-extras-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-branding-upstream-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-branding-upstream-2.12-150600.8.27.1">grub2-branding-upstream-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-i386-pc-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-i386-pc-2.12-150600.8.27.1">grub2-i386-pc-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-i386-pc-debug-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-i386-pc-debug-2.12-150600.8.27.1">grub2-i386-pc-debug-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-i386-pc-extras-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-i386-pc-extras-2.12-150600.8.27.1">grub2-i386-pc-extras-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-i386-xen-debug-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-i386-xen-debug-2.12-150600.8.27.1">grub2-i386-xen-debug-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-powerpc-ieee1275-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-powerpc-ieee1275-2.12-150600.8.27.1">grub2-powerpc-ieee1275-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-powerpc-ieee1275-debug-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-powerpc-ieee1275-debug-2.12-150600.8.27.1">grub2-powerpc-ieee1275-debug-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-powerpc-ieee1275-extras-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-powerpc-ieee1275-extras-2.12-150600.8.27.1">grub2-powerpc-ieee1275-extras-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-s390x-emu-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-s390x-emu-2.12-150600.8.27.1">grub2-s390x-emu-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-s390x-emu-debug-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-s390x-emu-debug-2.12-150600.8.27.1">grub2-s390x-emu-debug-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-s390x-emu-extras-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-s390x-emu-extras-2.12-150600.8.27.1">grub2-s390x-emu-extras-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-snapper-plugin-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-snapper-plugin-2.12-150600.8.27.1">grub2-snapper-plugin-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-systemd-sleep-plugin-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-systemd-sleep-plugin-2.12-150600.8.27.1">grub2-systemd-sleep-plugin-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-x86_64-efi-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-x86_64-efi-2.12-150600.8.27.1">grub2-x86_64-efi-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-x86_64-efi-debug-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-x86_64-efi-debug-2.12-150600.8.27.1">grub2-x86_64-efi-debug-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-x86_64-efi-extras-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-x86_64-efi-extras-2.12-150600.8.27.1">grub2-x86_64-efi-extras-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-x86_64-xen-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-x86_64-xen-2.12-150600.8.27.1">grub2-x86_64-xen-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-x86_64-xen-debug-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-x86_64-xen-debug-2.12-150600.8.27.1">grub2-x86_64-xen-debug-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="grub2-x86_64-xen-extras-2.12-150600.8.27.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:grub2-x86_64-xen-extras-2.12-150600.8.27.1">grub2-x86_64-xen-extras-2.12-150600.8.27.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. If an attacker with physical access can corrupt the underlying filesystem superblock, GRUB will fail to locate a valid filesystem and enter rescue mode. At this point, the disk is already decrypted, and the decryption key remains loaded in system memory. This scenario may allow an attacker with physical access to access the unencrypted data without any further authentication, thereby compromising data confidentiality. Furthermore, the ability to force this state through filesystem corruption also presents a data integrity concern.</Note>
    </Notes>
    <CVE>CVE-2025-4382</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-2.12-150600.8.27.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-arm64-efi-2.12-150600.8.27.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-i386-pc-2.12-150600.8.27.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-powerpc-ieee1275-2.12-150600.8.27.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-s390x-emu-2.12-150600.8.27.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-snapper-plugin-2.12-150600.8.27.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-systemd-sleep-plugin-2.12-150600.8.27.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP6:grub2-x86_64-efi-2.12-150600.8.27.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:grub2-x86_64-xen-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-arm64-efi-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-arm64-efi-debug-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-arm64-efi-extras-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-branding-upstream-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-i386-pc-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-i386-pc-debug-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-i386-pc-extras-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-i386-xen-debug-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-powerpc-ieee1275-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-powerpc-ieee1275-debug-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-powerpc-ieee1275-extras-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-s390x-emu-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-s390x-emu-debug-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-s390x-emu-extras-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-snapper-plugin-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-systemd-sleep-plugin-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-x86_64-efi-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-x86_64-efi-debug-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-x86_64-efi-extras-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-x86_64-xen-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-x86_64-xen-debug-2.12-150600.8.27.1</ProductID>
        <ProductID>openSUSE Leap 15.6:grub2-x86_64-xen-extras-2.12-150600.8.27.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202501615-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-4382.html</URL>
        <Description>CVE-2025-4382</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1242971</URL>
        <Description>SUSE Bug 1242971</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
