EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications.
Security Fix(es):
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
(CVE-2022-36763)
{
"severity": "High"
}{
"x86_64": [
"edk2-debuginfo-202011-19.oe2203sp3.x86_64.rpm",
"edk2-debugsource-202011-19.oe2203sp3.x86_64.rpm",
"edk2-devel-202011-19.oe2203sp3.x86_64.rpm"
],
"src": [
"edk2-202011-19.oe2203sp3.src.rpm"
],
"aarch64": [
"edk2-debuginfo-202011-19.oe2203sp3.aarch64.rpm",
"edk2-debugsource-202011-19.oe2203sp3.aarch64.rpm",
"edk2-devel-202011-19.oe2203sp3.aarch64.rpm"
],
"noarch": [
"edk2-aarch64-202011-19.oe2203sp3.noarch.rpm",
"edk2-help-202011-19.oe2203sp3.noarch.rpm",
"edk2-ovmf-202011-19.oe2203sp3.noarch.rpm",
"python3-edk2-devel-202011-19.oe2203sp3.noarch.rpm"
]
}