Marc Beatove discovered buffer overflows exit in EDK2. An attacker on the local network could potentially use this to impact availability or possibly cause remote code execution. (CVE-2022-36763, CVE-2022-36764, CVE-2022-36765)
It was discovered that a buffer overflows exists in EDK2's Network Package An attacker on the local network could potentially use these to impact availability or possibly cause remote code execution. (CVE-2023-45230, CVE-2023-45234, CVE-2023-45235)
It was discovered that an out-of-bounds read exists in EDK2's Network Package An attacker on the local network could potentially use this to impact confidentiality. (CVE-2023-45231)
It was discovered that infinite-loops exists in EDK2's Network Package An attacker on the local network could potentially use these to impact availability. (CVE-2023-45232, CVE-2023-45233)
Mate Kukri discovered that an insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. An attacker could use this to bypass Secure Boot. (CVE-2023-48733)
{ "availability": "No subscription required", "binaries": [ { "efi-shell-arm": "2023.05-2ubuntu0.1", "qemu-efi-arm": "2023.05-2ubuntu0.1", "ovmf-ia32": "2023.05-2ubuntu0.1", "efi-shell-ia32": "2023.05-2ubuntu0.1", "qemu-efi-aarch64": "2023.05-2ubuntu0.1", "efi-shell-x64": "2023.05-2ubuntu0.1", "ovmf": "2023.05-2ubuntu0.1", "efi-shell-aa64": "2023.05-2ubuntu0.1" } ] }