Issued:
2024-05-30
Updated:
2024-05-30

RHSA-2024:3497 - Important: edk2 security update


Synopsis

Important: edk2 security update

Type/Severity

Security Advisory: Important

Topic

An update for edk2 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM.

Security Fix(es):

  • edk2: Buffer overflow when processing DNS Servers option in a DHCPv6 Advertise message (CVE-2023-45234)

  • edk2: Buffer overflow in the DHCPv6 client via a long Server ID option (CVE-2023-45230)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

ProductVersionArch
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions8.6x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support8.6x86_64
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life8.6x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support8.6aarch64
Red Hat Enterprise Linux Server - TUS8.6x86_64
Red Hat Enterprise Linux Server - AUS8.6x86_64

Updated Packages

  • edk2-aarch64-20220126gitbb1bba3d77-2.el8_6.4.noarch.rpm
  • edk2-20220126gitbb1bba3d77-2.el8_6.4.src.rpm
  • edk2-ovmf-20220126gitbb1bba3d77-2.el8_6.4.noarch.rpm

Fixes

CVEs

References


Additional information