Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18465

Опубликовано: 08 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-18465: edk2 security update (IMPORTANT)

[20251114-5.0.1]

  • Replace upstream references [Orabug:36569119]

[20251114-5]

  • edk2-add-uefi-vars-firmware-json-files.patch [RHEL-150696]
  • Resolves: RHEL-150696 (edk2: Add JSON descriptors for uefi-vars builds)

[20251114-4]

  • edk2-OvmfPkg-X86QemuLoadImageLib-flip-default-for-EnableL.patch [RHEL-134956]
  • edk2-update-openssl-rhel-submodule.patch [RHEL-147785]
  • edk2-update-openssl-rhel-tarball.patch [RHEL-147785]
  • Resolves: RHEL-134956 (CVE-2025-2296 edk2: EDK2: Improper Input Validation allows arbitrary command execution [rhel-10.2])
  • Resolves: RHEL-147785 ([edk2] pick up openssl updates)

[20251114-3]

  • edk2-OvmfPkg-AmdSev-add-memory-debug-log-support.patch [RHEL-139470]
  • edk2-OvmfPkg-MemDebugLogPeiLib-drop-duplicate-MemDebugLog.patch [RHEL-139470]
  • edk2-OvmfPkg-MemDebugLogPeiCoreLib-enable-for-PEIMs.patch [RHEL-139470]
  • edk2-ArmVirtPkg-use-MemDebugLogPeiCoreLib-for-PEIMs.patch [RHEL-139470]
  • edk2-OvmfPkg-use-MemDebugLogPeiCoreLib-for-PEIMs.patch [RHEL-139470]
  • Resolves: RHEL-139470 (Enable memory debug logging support in firmware image configs)

[20251114-2]

  • edk2-ArmPkg-UefiCpuPkg-Fix-boot-failure-on-FEAT_LPA-only-.patch [RHEL-138335]
  • Resolves: RHEL-138335 ([AmpereoneX] ArmConfigureMmu: The MaxAddress 0xFFFFFFFFFFFFF is not supported by this MMU configuration)

[20251114-1]

  • Rebase to edk2-stable202511 [RHEL-118386]
  • Resolves: RHEL-118386 ([edk2,rhel-10] rebase to edk2-stable202511)

[20250822-4]

  • edk2-make-dbxupdate.sh-get-version-tag-add-to-commit-mess.patch [RHEL-126085]
  • edk2-update-dbx-to-20251016-v1.6.1.patch [RHEL-126085]
  • Resolves: RHEL-126085 ([edk2,rhel-10] dbx update to 20251016 / v1.6.1)

[20250822-3]

  • edk2-Bumped-OpenSSL-to-3.5.1-6.patch [RHEL-115880]
  • Resolves: RHEL-115880 (CVE-2025-9230 edk2: Out-of-bounds read & write in RFC 3211 KEK Unwrap [rhel-10.2])

[20250822-2]

  • edk2-add-DBXUpdate-20250610.aa64.bin.patch [RHEL-109548]
  • Resolves: RHEL-109548 ([aarch64][edk2] missing DBXUpdate-.aa64.bin)

[20250822-1]

  • Rebase to edk2-stable202508 [RHEL-111718]
  • Resolves: RHEL-111718 ([edk2,rhel-10] rebase to edk2-stable202508)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

edk2-aarch64

20251114-5.0.1.el10_2

edk2-ovmf

20251114-5.0.1.el10_2

edk2-tools

20251114-5.0.1.el10_2

edk2-tools-doc

20251114-5.0.1.el10_2

Oracle Linux x86_64

edk2-ovmf

20251114-5.0.1.el10_2

edk2-aarch64

20251114-5.0.1.el10_2

edk2-tools

20251114-5.0.1.el10_2

edk2-tools-doc

20251114-5.0.1.el10_2

Связанные CVE

Связанные уязвимости

ubuntu
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

CVSS3: 8.2
redhat
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

nvd
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

CVSS3: 8.2
msrc
8 месяцев назад

Un-verified kernel bypass Secure Boot mechanism in direct boot mode

debian
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause \u20 ...