OESA-2024-1350
Dashboard / Vulnerabilities / OESA-2024-1350
Summary: edk2 security update
Details: EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications. Security Fix(es): EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. (CVE-2022-36765)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1350, https://nvd.nist.gov/vuln/detail/CVE-2022-36765
Affected packages
Package
Name: edk2
Purl: pkg:rpm/openEuler/edk2&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
