Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-6919

Опубликовано: 17 нояб. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-6919: edk2 security and bug fix update (MODERATE)

[20220126gitbb1bba3d77-6]

  • edk2-UefiCpuPkg-MpInitLib-fix-apic-mode-for-cpu-hotplug.patch [bz#2150267]
  • Resolves: bz#2150267 (ovmf must consider max cpu count not boot cpu count for apic mode [rhel-8])

[20220126gitbb1bba3d77-5]

  • edk2-SecurityPkg-DxeImageVerificationLib-Check-result-of-.patch [bz#1861743]
  • Resolves: bz#1861743 (CVE-2019-14560 edk2: Function GetEfiGlobalVariable2() return value not checked in DxeImageVerificationHandler() [rhel-8])

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

edk2-aarch64

20220126gitbb1bba3d77-6.el8

Oracle Linux x86_64

edk2-ovmf

20220126gitbb1bba3d77-6.el8

Связанные CVE

Связанные уязвимости

CVSS3: 6.1
redhat
около 5 лет назад

[REJECTED CVE] A secure boot bypass vulnerability was found in EDK2 due to the lack of proper return value checks in the GetEfiGlobalVariable2() function. The API may fail if functions like AllocatePool() or gRT->GetVariable() fail. Without verifying the return value, an attacker could cause the API to fail, potentially bypassing secure boot. This issue occurs in functions like DxeImageVerificationHandler, where the return value is not checked.

nvd
больше 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

suse-cvrf
около 2 лет назад

Security update for ovmf

suse-cvrf
больше 2 лет назад

Security update for ovmf

suse-cvrf
больше 2 лет назад

Security update for ovmf