Описание
Moderate: edk2 security update
EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM.
Security Fix(es):
- edk2: possible heap corruption with LzmaUefiDecompressGetInfo (CVE-2021-28211)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Затронутые продукты
Rocky Linux 8
Связанные CVE
Исправления
- Red Hat - 1883529
Связанные уязвимости
CVSS3: 6.7
ubuntu
больше 4 лет назад
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
CVSS3: 6.7
redhat
около 5 лет назад
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
CVSS3: 6.7
nvd
больше 4 лет назад
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
CVSS3: 6.7
debian
больше 4 лет назад
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.