Description of the patch:
This update for grub2 fixes the following issues:
Security fixes and hardenings for boothole 3 / boothole 2022 (bsc#1198581)
CVE-2021-3695: Fixed that a crafted PNG grayscale image could lead to out-of-bounds write in heap (bsc#1191184)
CVE-2021-3696: Fixed that a crafted PNG image could lead to out-of-bound write during huffman table handling (bsc#1191185)
CVE-2021-3697: Fixed that a crafted JPEG image could lead to buffer underflow write in the heap (bsc#1191186)
CVE-2022-28733: Fixed fragmentation math in net/ip (bsc#1198460)
CVE-2022-28734: Fixed an out-of-bound write for split http headers (bsc#1198493)
CVE-2022-28736: Fixed a use-after-free in chainloader command (bsc#1198496)
Update SBAT security contact (bsc#1193282)
Bump grub's SBAT generation to 2
Use boot disks in OpenFirmware, fixing regression caused when the root LV is completely in the boot LUN (bsc#1197948)
2.02-137.22.02-137.22.02-137.22.02-137.22.02-137.22.02-137.22.02-137.22.02-137.22.02-137.2Exploitability
AV:NAC:LPR:NUI:RScope
S:UImpact
C:HI:HA:H8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H