Описание
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
A flaw was found in edk2. Missing checks in the IScsiHexToBin function in NetworkPkg/IScsiDxe lead to a buffer overflow allowing a remote attacker, who can inject himself in the communication between edk2 and the iSCSI target, to write arbitrary data to any address in the edk2 firmware and potentially execute code. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | ovmf | Affected | ||
Red Hat Enterprise Linux 9 | edk2 | Not affected | ||
Red Hat Enterprise Linux 8 | edk2 | Fixed | RHSA-2021:3066 | 10.08.2021 |
Red Hat Enterprise Linux 8.1 Extended Update Support | edk2 | Fixed | RHSA-2021:3172 | 17.08.2021 |
Red Hat Enterprise Linux 8.2 Extended Update Support | edk2 | Fixed | RHSA-2021:3369 | 31.08.2021 |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host | Fixed | RHSA-2021:3235 | 19.08.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
EPSS
8.1 High
CVSS3