Описание
Security update for ovmf
This update for ovmf fixes the following issues:
- Fixed a possible buffer overflow in IScsiDxe (bsc#1186151)
- CVE-2021-28211: ovmf: edk2: possible heap corruption with LzmaUefiDecompressGetInfo (bsc#1183578)
- CVE-2021-28210: ovmf: unlimited FV recursion, round 2 (bsc#1183579)
- CVE-2019-14584: ovmf,shim: NULL pointer dereference in AuthenticodeVerify() (bsc#1177789)
Список пакетов
SUSE Linux Enterprise Server 12 SP2-BCL
ovmf-2015+git1462940744.321151f-19.23.1
ovmf-tools-2015+git1462940744.321151f-19.23.1
qemu-ovmf-x86_64-2015+git1462940744.321151f-19.23.1
Ссылки
- Link for SUSE-SU-2021:2117-1
- E-Mail link for SUSE-SU-2021:2117-1
- SUSE Security Ratings
- SUSE Bug 1177789
- SUSE Bug 1183578
- SUSE Bug 1183579
- SUSE Bug 1186151
- SUSE CVE CVE-2019-14584 page
- SUSE CVE CVE-2021-28210 page
- SUSE CVE CVE-2021-28211 page
Описание
Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:ovmf-2015+git1462940744.321151f-19.23.1
SUSE Linux Enterprise Server 12 SP2-BCL:ovmf-tools-2015+git1462940744.321151f-19.23.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-ovmf-x86_64-2015+git1462940744.321151f-19.23.1
Ссылки
- CVE-2019-14584
- SUSE Bug 1177789
Описание
An unlimited recursion in DxeCore in EDK II.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:ovmf-2015+git1462940744.321151f-19.23.1
SUSE Linux Enterprise Server 12 SP2-BCL:ovmf-tools-2015+git1462940744.321151f-19.23.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-ovmf-x86_64-2015+git1462940744.321151f-19.23.1
Ссылки
- CVE-2021-28210
- SUSE Bug 1183579
Описание
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:ovmf-2015+git1462940744.321151f-19.23.1
SUSE Linux Enterprise Server 12 SP2-BCL:ovmf-tools-2015+git1462940744.321151f-19.23.1
SUSE Linux Enterprise Server 12 SP2-BCL:qemu-ovmf-x86_64-2015+git1462940744.321151f-19.23.1
Ссылки
- CVE-2021-28211
- SUSE Bug 1183578