Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:2591

Опубликовано: 29 июн. 2021
Источник: rocky
Оценка: Moderate

Описание

Moderate: edk2 security update

EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM.

Security Fix(es):

  • edk2: possible heap corruption with LzmaUefiDecompressGetInfo (CVE-2021-28211)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
edk2-ovmfnoarch4.el8_4.1edk2-ovmf-20200602gitca407c7246bf-4.el8_4.1.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 4 лет назад

A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.

CVSS3: 6.7
redhat
около 5 лет назад

A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.

CVSS3: 6.7
nvd
больше 4 лет назад

A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.

msrc
3 месяца назад

A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.

CVSS3: 6.7
debian
больше 4 лет назад

A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.