OESA-2021-1358

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1358
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1358.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2021-1358
Upstream
Published
2021-09-30T11:03:13Z
Modified
2025-09-03T06:17:35.261704Z
Summary
edk2 security update
Details

EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications.

Security Fix(es):

A flaw was found in edk2. Missing checks in the IScsiHexToBin function in NetworkPkg/IScsiDxe lead to a buffer overflow allowing a remote attacker, who can inject himself in the communication between edk2 and the iSCSI target, to write arbitrary data to any address in the edk2 firmware and potentially execute code. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2021-38575)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / edk2

Package

Name
edk2
Purl
pkg:rpm/openEuler/edk2&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
202002-6.oe1

Ecosystem specific

{
    "aarch64": [
        "edk2-devel-202002-6.oe1.aarch64.rpm",
        "edk2-debugsource-202002-6.oe1.aarch64.rpm",
        "edk2-debuginfo-202002-6.oe1.aarch64.rpm"
    ],
    "src": [
        "edk2-202002-6.oe1.src.rpm"
    ],
    "x86_64": [
        "edk2-devel-202002-6.oe1.x86_64.rpm",
        "edk2-debugsource-202002-6.oe1.x86_64.rpm",
        "edk2-debuginfo-202002-6.oe1.x86_64.rpm"
    ],
    "noarch": [
        "python3-edk2-devel-202002-6.oe1.noarch.rpm",
        "edk2-help-202002-6.oe1.noarch.rpm",
        "edk2-aarch64-202002-6.oe1.noarch.rpm",
        "edk2-ovmf-202002-6.oe1.noarch.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / edk2

Package

Name
edk2
Purl
pkg:rpm/openEuler/edk2&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
202002-6.oe1

Ecosystem specific

{
    "aarch64": [
        "edk2-debugsource-202002-6.oe1.aarch64.rpm",
        "edk2-devel-202002-6.oe1.aarch64.rpm",
        "edk2-debuginfo-202002-6.oe1.aarch64.rpm"
    ],
    "src": [
        "edk2-202002-6.oe1.src.rpm"
    ],
    "x86_64": [
        "edk2-debuginfo-202002-6.oe1.x86_64.rpm",
        "edk2-devel-202002-6.oe1.x86_64.rpm",
        "edk2-debugsource-202002-6.oe1.x86_64.rpm"
    ],
    "noarch": [
        "python3-edk2-devel-202002-6.oe1.noarch.rpm",
        "edk2-help-202002-6.oe1.noarch.rpm",
        "edk2-aarch64-202002-6.oe1.noarch.rpm",
        "edk2-ovmf-202002-6.oe1.noarch.rpm"
    ]
}