edk2-20200602gitca407c7246bf-4.el8.1

エラータID: AXSA:2021-2183:03

Release date: 
Monday, July 12, 2021 - 06:18
Subject: 
edk2-20200602gitca407c7246bf-4.el8.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM.

Security Fix(es):

* edk2: possible heap corruption with LzmaUefiDecompressGetInfo (CVE-2021-28211)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-28211
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. edk2-20200602gitca407c7246bf-4.el8.1.src.rpm
    MD5: 642af83a03d9fe2b1f3098da5638aeca
    SHA-256: 5ad1a3a507291e48583dde7a32c2194695f4e86ed9c2f80101c767c2f163b1e0
    Size: 13.68 MB

Asianux Server 8 for x86_64
  1. edk2-ovmf-20200602gitca407c7246bf-4.el8.1.noarch.rpm
    MD5: 0058532decdffbe43213118b5bb7778d
    SHA-256: ab8e120387d746b0d3f8646d93a43b0dc108f732d5f603a9d583332c1a33bccf
    Size: 1.98 MB