Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:18465

Опубликовано: 29 мая 2026
Источник: rocky
Оценка: Important

Описание

Important: edk2 security update

EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM.

Security Fix(es):

  • edk2: EDK2: Improper Input Validation allows arbitrary command execution (CVE-2025-2296)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
edk2-ovmfnoarch5.el10edk2-ovmf-20251114-5.el10.noarch.rpm
edk2-aarch64noarch5.el10edk2-aarch64-20251114-5.el10.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

ubuntu
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

CVSS3: 8.2
redhat
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

nvd
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

CVSS3: 8.2
msrc
8 месяцев назад

Un-verified kernel bypass Secure Boot mechanism in direct boot mode

debian
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause \u20 ...