grub2/grub.patches
Qiumiao Zhang e2ff5149fb fix CVE-2024-56738
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit aab76ae0eaebd92ac60f8c9f9b07728734b40bfb)
2025-04-08 09:12:43 +08:00

328 lines
22 KiB
Plaintext

Patch1: rename-grub-info-file-to-grub2.patch
Patch2: grub2-linux.patch
#Patch3: use-grub2-as-a-package-name.patch
Patch4: info-dir-entry.patch
Patch5: grub2-simplefb.patch
Patch6: grub2-iterate-and-hook-for-extended-partition.patch
Patch7: grub2-ppc-terminfo.patch
Patch8: grub2-fix-error-terminal-gfxterm-isn-t-found.patch
Patch9: grub2-fix-menu-in-xen-host-server.patch
Patch10: not-display-menu-when-boot-once.patch
Patch11: grub2-pass-corret-root-for-nfsroot.patch
Patch12: grub2-efi-HP-workaround.patch
Patch13: grub2-secureboot-add-linuxefi.patch
Patch14: grub2-secureboot-no-insmod-on-sb.patch
Patch15: grub2-secureboot-chainloader.patch
Patch16: grub2-linuxefi-fix-boot-params.patch
Patch17: grub2-linguas.sh-no-rsync.patch
Patch18: grub2-use-Unifont-for-starfield-theme-terminal.patch
Patch19: grub2-s390x-01-Changes-made-and-files-added-in-order-to-allow-s390x.patch
Patch20: grub2-s390x-03-output-7-bit-ascii.patch
Patch21: grub2-s390x-04-grub2-install.patch
Patch22: grub2-s390x-05-grub2-mkconfig.patch
Patch23: grub2-use-rpmsort-for-version-sorting.patch
Patch24: grub2-getroot-treat-mdadm-ddf-as-simple-device.patch
Patch25: grub2-setup-try-fs-embed-if-mbr-gap-too-small.patch
Patch26: grub2-xen-linux16.patch
Patch27: grub2-efi-disable-video-cirrus-and-bochus.patch
Patch28: grub2-vbe-blacklist-preferred-1440x900x32.patch
Patch29: grub2-grubenv-in-btrfs-header.patch
Patch30: grub2-mkconfig-aarch64.patch
Patch31: grub2-default-distributor.patch
Patch32: grub2-menu-unrestricted.patch
Patch33: grub2-mkconfig-arm.patch
Patch34: grub2-s390x-06-loadparm.patch
Patch35: grub2-s390x-07-add-image-param-for-zipl-setup.patch
Patch36: grub2-s390x-08-workaround-part-to-disk.patch
Patch37: grub2-commands-introduce-read_file-subcommand.patch
Patch38: grub2-efi-chainload-harder.patch
Patch39: grub2-emu-4-all.patch
Patch40: grub2-lvm-allocate-metadata-buffer-from-raw-contents.patch
Patch41: grub2-diskfilter-support-pv-without-metadatacopies.patch
Patch42: grub2-s390x-09-improve-zipl-setup.patch
Patch43: grub2-getroot-scan-disk-pv.patch
Patch44: grub2-util-30_os-prober-multiple-initrd.patch
Patch45: grub2-getroot-support-nvdimm.patch
Patch46: grub2-install-fix-not-a-directory-error.patch
Patch47: grub-install-force-journal-draining-to-ensure-data-i.patch
Patch48: grub2-s390x-skip-zfcpdump-image.patch
Patch49: grub2-btrfs-01-add-ability-to-boot-from-subvolumes.patch
Patch50: grub2-btrfs-02-export-subvolume-envvars.patch
Patch51: grub2-btrfs-03-follow_default.patch
Patch52: grub2-btrfs-04-grub2-install.patch
Patch53: grub2-btrfs-05-grub2-mkconfig.patch
Patch54: grub2-btrfs-06-subvol-mount.patch
Patch55: grub2-btrfs-07-subvol-fallback.patch
Patch56: grub2-btrfs-08-workaround-snapshot-menu-default-entry.patch
Patch57: grub2-btrfs-09-get-default-subvolume.patch
Patch58: grub2-btrfs-10-config-directory.patch
Patch59: grub2-efi-xen-chainload.patch
Patch60: grub2-efi-xen-cmdline.patch
Patch61: grub2-efi-xen-cfg-unquote.patch
Patch62: grub2-efi-xen-removable.patch
Patch63: grub2-Add-hidden-menu-entries.patch
Patch64: grub2-SUSE-Add-the-t-hotkey.patch
Patch65: grub2-zipl-setup-fix-btrfs-multipledev.patch
Patch66: grub2-suse-remove-linux-root-param.patch
Patch67: grub2-ppc64le-disable-video.patch
Patch68: grub2-ppc64le-memory-map.patch
Patch69: grub2-ppc64-cas-reboot-support.patch
Patch70: grub2-install-remove-useless-check-PReP-partition-is-empty.patch
Patch71: grub2-ppc64-cas-new-scope.patch
Patch72: grub2-ppc64-cas-fix-double-free.patch
Patch73: grub2-efi_gop-avoid-low-resolution.patch
Patch74: 0003-bootp-New-net_bootp6-command.patch
Patch75: 0004-efinet-UEFI-IPv6-PXE-support.patch
Patch76: 0005-grub.texi-Add-net_bootp6-doument.patch
Patch77: 0006-bootp-Add-processing-DHCPACK-packet-from-HTTP-Boot.patch
Patch78: 0007-efinet-Setting-network-from-UEFI-device-path.patch
Patch79: 0008-efinet-Setting-DNS-server-from-UEFI-protocol.patch
Patch80: 0012-tpm-Build-tpm-as-module.patch
Patch81: 0001-add-support-for-UEFI-network-protocols.patch
Patch82: 0002-AUDIT-0-http-boot-tracker-bug.patch
Patch83: grub2-mkconfig-default-entry-correction.patch
Patch84: grub2-s390x-11-secureboot.patch
Patch85: grub2-s390x-12-zipl-setup-usrmerge.patch
Patch86: grub2-secureboot-install-signed-grub.patch
Patch87: grub2-btrfs-help-on-snapper-rollback.patch
Patch88: grub2-video-limit-the-resolution-for-fixed-bimap-font.patch
Patch89: grub2-gfxmenu-support-scrolling-menu-entry-s-text.patch
Patch90: 0001-kern-mm.c-Make-grub_calloc-inline.patch
Patch91: 0002-cmdline-Provide-cmdline-functions-as-module.patch
Patch92: 0001-ieee1275-powerpc-implements-fibre-channel-discovery-.patch
Patch93: 0002-ieee1275-powerpc-enables-device-mapper-discovery.patch
Patch94: 0001-Unify-the-check-to-enable-btrfs-relative-path.patch
Patch95: 0001-efi-linux-provide-linux-command.patch
Patch96: 0001-Add-support-for-Linux-EFI-stub-loading-on-aarch64.patch
Patch97: 0002-arm64-make-sure-fdt-has-address-cells-and-size-cells.patch
Patch98: 0003-Make-grub_error-more-verbose.patch
Patch99: 0004-arm-arm64-loader-Better-memory-allocation-and-error-.patch
Patch100: 0006-efi-Set-image-base-address-before-jumping-to-the-PE-.patch
Patch101: 0044-squash-kern-Add-lockdown-support.patch
Patch102: 0001-ieee1275-Avoiding-many-unecessary-open-close.patch
Patch103: 0001-Workaround-volatile-efi-boot-variable.patch
Patch104: 0001-templates-Follow-the-path-of-usr-merged-kernel-confi.patch
Patch105: 0001-ieee1275-implement-FCP-methods-for-WWPN-and-LUNs.patch
Patch106: 0001-arm64-Fix-EFI-loader-kernel-image-allocation.patch
Patch107: 0002-Arm-check-for-the-PE-magic-for-the-compiled-arch.patch
Patch108: 0001-Factor-out-grub_efi_linux_boot.patch
Patch109: 0002-Fix-race-in-EFI-validation.patch
Patch110: 0003-Handle-multi-arch-64-on-32-boot-in-linuxefi-loader.patch
Patch111: 0004-Try-to-pick-better-locations-for-kernel-and-initrd.patch
Patch112: 0005-x86-efi-Use-bounce-buffers-for-reading-to-addresses-.patch
Patch113: 0006-x86-efi-Re-arrange-grub_cmd_linux-a-little-bit.patch
Patch114: 0007-x86-efi-Make-our-own-allocator-for-kernel-stuff.patch
Patch115: 0008-x86-efi-Allow-initrd-params-cmdline-allocations-abov.patch
Patch116: 0009-x86-efi-Reduce-maximum-bounce-buffer-size-to-16-MiB.patch
Patch117: 0010-efilinux-Fix-integer-overflows-in-grub_cmd_initrd.patch
Patch118: 0011-Also-define-GRUB_EFI_MAX_ALLOCATION_ADDRESS-for-RISC.patch
Patch119: 0004-Add-suport-for-signing-grub-with-an-appended-signatu.patch
Patch120: 0005-docs-grub-Document-signing-grub-under-UEFI.patch
Patch121: 0006-docs-grub-Document-signing-grub-with-an-appended-sig.patch
Patch122: 0007-dl-provide-a-fake-grub_dl_set_persistent-for-the-emu.patch
Patch123: 0008-pgp-factor-out-rsa_pad.patch
Patch124: 0009-crypto-move-storage-for-grub_crypto_pk_-to-crypto.c.patch
Patch125: 0010-posix_wrap-tweaks-in-preparation-for-libtasn1.patch
Patch126: 0011-libtasn1-import-libtasn1-4.18.0.patch
Patch127: 0012-libtasn1-disable-code-not-needed-in-grub.patch
Patch128: 0013-libtasn1-changes-for-grub-compatibility.patch
Patch129: 0014-libtasn1-compile-into-asn1-module.patch
Patch130: 0015-test_asn1-test-module-for-libtasn1.patch
Patch131: 0016-grub-install-support-embedding-x509-certificates.patch
Patch132: 0017-appended-signatures-import-GNUTLS-s-ASN.1-descriptio.patch
Patch133: 0018-appended-signatures-parse-PKCS-7-signedData-and-X.50.patch
Patch134: 0019-appended-signatures-support-verifying-appended-signa.patch
Patch135: 0020-appended-signatures-verification-tests.patch
Patch136: 0021-appended-signatures-documentation.patch
Patch137: 0022-ieee1275-enter-lockdown-based-on-ibm-secure-boot.patch
Patch138: 0023-x509-allow-Digitial-Signature-plus-other-Key-Usages.patch
Patch139: 0001-grub-install-Add-SUSE-signed-image-support-for-power.patch
Patch140: 0001-Add-grub_envblk_buf-helper-function.patch
Patch141: 0002-Add-grub_disk_write_tail-helper-function.patch
Patch142: 0003-grub-install-support-prep-environment-block.patch
Patch143: 0004-Introduce-prep_load_env-command.patch
Patch144: 0005-export-environment-at-start-up.patch
Patch145: 0001-grub-install-bailout-root-device-probing.patch
Patch146: 0001-install-fix-software-raid1-on-esp.patch
Patch147: 0001-grub-probe-Deduplicate-probed-partmap-output.patch
Patch148: 0001-Fix-infinite-boot-loop-on-headless-system-in-qemu.patch
Patch149: 0001-ofdisk-improve-boot-time-by-lookup-boot-disk-first.patch
Patch150: 0001-protectors-Add-key-protectors-framework.patch
Patch151: 0002-tpm2-Add-TPM-Software-Stack-TSS.patch
Patch152: 0003-protectors-Add-TPM2-Key-Protector.patch
Patch153: 0004-cryptodisk-Support-key-protectors.patch
Patch154: 0005-util-grub-protect-Add-new-tool.patch
Patch155: 0008-linuxefi-Use-common-grub_initrd_load.patch
Patch156: 0009-Add-crypttab_entry-to-obviate-the-need-to-input-pass.patch
Patch157: 0010-templates-import-etc-crypttab-to-grub.cfg.patch
Patch158: grub-read-pcr.patch
Patch159: tpm-record-pcrs.patch
Patch160: grub-install-record-pcrs.patch
Patch161: safe_tpm_pcr_snapshot.patch
Patch162: 0001-ieee1275-add-support-for-NVMeoFC.patch
Patch163: 0002-ieee1275-ofpath-enable-NVMeoF-logical-device-transla.patch
Patch164: 0003-ieee1275-change-the-logic-of-ieee1275_get_devargs.patch
Patch165: 0004-ofpath-controller-name-update.patch
Patch166: 0002-Mark-environmet-blocks-as-used-for-image-embedding.patch
Patch167: grub2-increase-crypttab-path-buffer.patch
Patch168: 0001-grub2-Set-multiple-device-path-for-a-nvmf-boot-devic.patch
Patch169: 0001-grub2-Can-t-setup-a-default-boot-device-correctly-on.patch
Patch170: 0001-tpm2-Add-TPM2-types-structures-and-command-constants.patch
Patch171: 0002-tpm2-Add-more-marshal-unmarshal-functions.patch
Patch172: 0003-tpm2-Implement-more-TPM2-commands.patch
Patch173: 0004-tpm2-Support-authorized-policy.patch
Patch174: 0001-clean-up-crypttab-and-linux-modules-dependency.patch
Patch175: 0002-discard-cached-key-before-entering-grub-shell-and-ed.patch
Patch176: 0001-ieee1275-ofdisk-retry-on-open-and-read-failure.patch
Patch177: 0002-Restrict-cryptsetup-key-file-permission-for-better-s.patch
Patch178: 0001-openfw-Ensure-get_devargs-and-get_devname-functions-.patch
Patch179: 0002-prep_loadenv-Fix-regex-for-Open-Firmware-device-spec.patch
Patch180: 0001-xen_boot-add-missing-grub_arch_efi_linux_load_image_.patch
Patch181: 0001-font-Try-memdisk-fonts-with-the-same-name.patch
Patch182: 0001-Make-grub.cfg-compatible-to-old-binaries.patch
Patch183: grub2-change-bash-completion-dir.patch
Patch184: 0001-protectors-Implement-NV-index.patch
Patch185: 0002-cryptodisk-Fallback-to-passphrase.patch
Patch186: 0003-cryptodisk-wipe-out-the-cached-keys-from-protectors.patch
Patch187: 0004-diskfilter-look-up-cryptodisk-devices-first.patch
Patch188: grub2-mkconfig-riscv64.patch
Patch189: arm64-Use-proper-memory-type-for-kernel-allocation.patch
Patch190: 0001-luks2-Use-grub-tpm2-token-for-TPM2-protected-volume-.patch
Patch191: Fix-the-size-calculation-for-the-synthesized-initrd.patch
Patch192: 0001-Improve-TPM-key-protection-on-boot-interruptions.patch
Patch193: 0002-Restrict-file-access-on-cryptodisk-print.patch
Patch194: 0003-Restrict-ls-and-auto-file-completion-on-cryptodisk-p.patch
Patch195: 0004-Key-revocation-on-out-of-bound-file-access.patch
Patch196: fix_no_extra_deps_in_release_tarball.patch
Patch197: 0001-fs-xfs-always-verify-the-total-number-of-entries-is-.patch
Patch198: 0001-loader-arm64-efi-linux-Remove-magic-number-header-fi.patch
Patch199: 0001-squash-ieee1275-ofpath-enable-NVMeoF-logical-device-.patch
Patch200: 0001-ofdisk-enhance-boot-time-by-focusing-on-boot-disk-re.patch
Patch201: 0002-ofdisk-add-early_log-support.patch
Patch202: 0001-disk-Optimize-disk-iteration-by-moving-memdisk-to-th.patch
Patch203: grub2-bash-completion-2.12.patch
Patch204: 0010-re-write-.gitignore.patch
Patch205: disable-some-unsupported-filesystems.patch
Patch206: remove-the-items-of-unsupported-filesystems-in-fs.ls.patch
Patch207: backport-Read-etc-default-grub.d-.cfg-after-etc-default-grub.patch
Patch208: modify-klist-in-10_linux.in.patch
Patch209: 0019-Add-fw_path-variable-revised.patch
Patch210: 0024-Don-t-say-GNU-Linux-in-generated-menus.patch
Patch211: 0026-Don-t-require-a-password-to-boot-entries-generated-b.patch
Patch212: 0028-use-fw_path-prefix-when-fallback-searching-for-grub-.patch
Patch213: 0029-Try-mac-guid-etc-before-grub.cfg-on-tftp-config-file.patch
Patch214: 0030-Generate-OS-and-CLASS-in-10_linux-from-etc-os-releas.patch
Patch215: 0032-Try-prefix-if-fw_path-doesn-t-work.patch
Patch216: 0034-Make-grub2-mkconfig-construct-titles-that-look-like-.patch
Patch217: 0035-Add-friendly-grub2-password-config-tool-985962.patch
Patch218: grub2-set-password-prompts-to-enter-the-current-pass.patch
Patch219: add-TPCM-support-with-ipmi-channel.patch
Patch220: skip-verification-when-not-loading-grub.cfg.patch
Patch221: fix-setupmode-not-available-in-some-machine.patch
Patch222: fix-compressed-kernel-verification-failed.patch
Patch223: support-TPM2.0.patch
Patch224: use-default-timestamp.patch
Patch225: 0027-Replace-a-lot-of-man-pages-with-slightly-nicer-ones.patch
Patch226: 0038-Add-grub-get-kernel-settings-and-use-it-in-10_linux.patch
Patch227: 0084-grub-editenv-Add-incr-command-to-increment-integer-v.patch
Patch228: 0002-Revert-templates-Properly-disable-the-os-prober-by-d.patch
Patch229: 0003-Revert-templates-Disable-the-os-prober-by-default.patch
Patch230: Handle-non-continuous-data-blocks-in-directory-exten.patch
Patch231: loongarch64-fix-GRUB_EFI_MAX_ALLOCATION_ADDRESS-unde.patch
Patch233: LoongArch-Add-back-compatibility-for-linux-kernel.patch
Patch234: Fix-that-patch-28dcf48482-introduced-old-code.patch
Patch235: backport-CVE-2021-46848-lib-libtasn1-Fix-ETYPE_OK-off-by-one-array.patch
Patch236: backport-disk-mdraid1x_linux-Prevent-infinite-recursion.patch
Patch237: backport-Export-all-variables-from-the-initial-context-when-c.patch
Patch238: grub2-ppc64le-fix-bug-about-petitboot-doesn-t-ignore-EFI-entries.patch
Patch239: 0021-blscfg-add-blscfg-module-to-parse-Boot-Loader-Specif.patch
Patch240: 0061-Add-BLS-support-to-grub-mkconfig.patch
Patch241: 0064-Add-grub2-switch-to-blscfg.patch
Patch242: 0001-newfeature-tpcm-add-hygon-tpcm-support.patch
Patch243: 10_linux-fix-missing-ro-in-kernel-boot-parameters.patch
Patch244: 0001-cryptodisk-add-OS-provided-secret-support.patch
Patch245: 0002-efi-Add-API-for-retrieving-the-EFI-secret-for-crypto.patch
Patch246: backport-acpi-Fix-out-of-bounds-access-in-grub_acpi_xsdt_find.patch
Patch247: backport-commands-efi-tpm-Re-enable-measurements-on-confident.patch
Patch248: backport-commands-legacycfg-Avoid-closing-file-twice.patch
Patch249: bugfix-fix-not-verifying-grub-cfg-when-loading-it.patch
Patch250: backport-0001-misc-Implement-grub_strlcpy.patch
Patch251: backport-0002-fs-ufs-Fix-a-heap-OOB-write.patch
Patch252: backport-0003-fs-hfs-Fix-stack-OOB-write-with-grub_strcpy.patch
Patch253: backport-0004-fs-tar-Initialize-name-in-grub_cpio_find_file.patch
Patch254: backport-0005-fs-tar-Integer-overflow-leads-to-heap-OOB-write.patch
Patch255: backport-0006-fs-f2fs-Set-a-grub_errno-if-mount-fails.patch
Patch256: backport-0007-fs-hfsplus-Set-a-grub_errno-if-mount-fails.patch
Patch257: backport-0008-fs-iso9660-Set-a-grub_errno-if-mount-fails.patch
Patch258: backport-0009-fs-iso9660-Fix-invalid-free.patch
Patch259: backport-0010-fs-jfs-Fix-OOB-read-in-jfs_getent.patch
Patch260: backport-0011-fs-jfs-Fix-OOB-read-caused-by-invalid-dir-slot-index.patch
Patch261: backport-0012-fs-jfs-Use-full-40-bits-offset-and-address-for-a-dat.patch
Patch262: backport-0013-fs-jfs-Inconsistent-signed-unsigned-types-usage-in-r.patch
Patch263: backport-0014-fs-ext2-Fix-out-of-bounds-read-for-inline-extents.patch
Patch264: backport-0015-fs-ntfs-Fix-out-of-bounds-read.patch
Patch265: backport-0016-fs-ntfs-Track-the-end-of-the-MFT-attribute-buffer.patch
Patch266: backport-0017-fs-ntfs-Use-a-helper-function-to-access-attributes.patch
Patch267: backport-0018-fs-ntfs-Implement-attribute-verification.patch
Patch268: backport-0019-fs-xfs-Fix-out-of-bounds-read.patch
Patch269: backport-0020-fs-xfs-Ensuring-failing-to-mount-sets-a-grub_errno.patch
Patch270: backport-0021-kern-file-Ensure-file-data-is-set.patch
Patch271: backport-0022-kern-file-Implement-filesystem-reference-counting.patch
Patch272: backport-0023-disk-cryptodisk-Require-authentication-after-TPM-unl.patch
Patch273: backport-0024-disk-loopback-Reference-tracking-for-the-loopback.patch
Patch274: backport-0025-kern-disk-Limit-recursion-depth.patch
Patch275: backport-0026-kern-partition-Limit-recursion-in-part_iterate.patch
Patch276: backport-0027-script-execute-Limit-the-recursion-depth.patch
Patch277: backport-0028-net-Unregister-net_default_ip-and-net_default_mac-va.patch
Patch278: backport-0029-net-Remove-variables-hooks-when-interface-is-unregis.patch
Patch279: backport-0030-net-Fix-OOB-write-in-grub_net_search_config_file.patch
Patch280: backport-0031-net-tftp-Fix-stack-buffer-overflow-in-tftp_open.patch
Patch281: backport-0032-video-readers-jpeg-Do-not-permit-duplicate-SOF0-mark.patch
Patch282: backport-0033-kern-dl-Fix-for-an-integer-overflow-in-grub_dl_ref.patch
Patch283: backport-0034-fs-ext2-Rework-out-of-bounds-read-for-inline-and-external.patch
Patch284: backport-0035-kern-dl-Check-for-the-SHF_INFO_LINK-flag-in-grub_dl_.patch
Patch285: backport-0036-commands-extcmd-Missing-check-for-failed-allocation.patch
Patch286: backport-0037-commands-ls-Fix-NULL-dereference.patch
Patch287: backport-0038-commands-pgp-Unregister-the-check_signatures-hooks-o.patch
Patch288: backport-0039-normal-Remove-variables-hooks-on-module-unload.patch
Patch289: backport-0040-gettext-Remove-variables-hooks-on-module-unload.patch
Patch290: backport-0041-gettext-Integer-overflow-leads-to-heap-OOB-write-or-.patch
Patch291: backport-0042-gettext-Integer-overflow-leads-to-heap-OOB-write.patch
Patch292: backport-0043-commands-read-Fix-an-integer-overflow-when-supplying.patch
Patch293: backport-0044-commands-test-Stack-overflow-due-to-unlimited-recurs.patch
Patch294: backport-0045-commands-minicmd-Block-the-dump-command-in-lockdown-.patch
Patch295: backport-0046-commands-memrw-Disable-memory-reading-in-lockdown-mo.patch
Patch296: backport-0047-commands-hexdump-Disable-memory-reading-in-lockdown-.patch
Patch297: backport-0048-fs-bfs-Disable-under-lockdown.patch
Patch298: backport-0049-fs-Disable-many-filesystems-under-lockdown.patch
Patch299: backport-0050-disk-Use-safe-math-macros-to-prevent-overflows.patch
Patch300: backport-0051-disk-Prevent-overflows-when-allocating-memory-for-ar.patch
Patch301: backport-0052-disk-Check-if-returned-pointer-for-allocated-memory-.patch
Patch302: backport-0053-disk-ieee1275-ofdisk-Call-grub_ieee1275_close-when-g.patch
Patch303: backport-0054-fs-Use-safe-math-macros-to-prevent-overflows.patch
Patch304: backport-0055-fs-Prevent-overflows-when-allocating-memory-for-arra.patch
Patch305: backport-0056-fs-Prevent-overflows-when-assigning-returned-values-.patch
Patch306: backport-0057-fs-zfs-Use-safe-math-macros-to-prevent-overflows.patch
Patch307: backport-0058-fs-zfs-Prevent-overflows-when-allocating-memory-for-.patch
Patch308: backport-0059-fs-zfs-Check-if-returned-pointer-for-allocated-memor.patch
Patch309: backport-0060-fs-zfs-Add-missing-NULL-check-after-grub_strdup-call.patch
Patch310: backport-0061-net-Use-safe-math-macros-to-prevent-overflows.patch
Patch311: backport-0062-net-Prevent-overflows-when-allocating-memory-for-arr.patch
Patch312: backport-0063-net-Check-if-returned-pointer-for-allocated-memory-i.patch
Patch313: backport-0064-fs-sfs-Check-if-allocated-memory-is-NULL.patch
Patch314: backport-0065-script-execute-Fix-potential-underflow-and-NULL-dere.patch
Patch315: backport-0066-osdep-unix-getroot-Fix-potential-underflow.patch
Patch316: backport-0067-misc-Ensure-consistent-overflow-error-messages.patch
Patch317: backport-0068-bus-usb-ehci-Define-GRUB_EHCI_TOGGLE-as-grub_uint32_.patch
Patch318: backport-0069-normal-menu-Use-safe-math-to-avoid-an-integer-overfl.patch
Patch319: backport-0070-kern-partition-Add-sanity-check-after-grub_strtoul-c.patch
Patch320: backport-0071-kern-misc-Add-sanity-check-after-grub_strtoul-call.patch
Patch321: backport-0072-loader-i386-linux-Cast-left-shift-to-grub_uint32_t.patch
Patch322: backport-0073-loader-i386-bsd-Use-safe-math-to-avoid-underflow.patch
Patch323: sw64-Add-early-startup-code.patch
Patch324: sw64-Add-Linux-load-logic.patch
Patch325: sw64-Add-awareness-for-SW64-reloations.patch
Patch326: sw64-Add-auxiliary-files.patch
Patch327: sw64-Add-to-build-system.patch
Patch328: backport-fix-CVE-2024-56738.patch