ELSA-2024-4749

ELSA-2024-4749 - edk2 security update

Type:SECURITY
Severity:MODERATE
Release Date:2024-07-24

Description


[20231122-6.0.1.el9_4.2]
- Replace upstream references [Orabug:36569119]

[20231122-6.el9_4.2]
- edk2-NetworkPkg-SECURITY-PATCH-CVE-2023-45237.patch [RHEL-40270 RHEL-40272]
- edk2-NetworkPkg-TcpDxe-SECURITY-PATCH-CVE-2023-45236.patch [RHEL-40270 RHEL-40272]
- edk2-NetworkPkg-TcpDxe-Fixed-system-stuck-on-PXE-boot-flo.patch [RHEL-40270 RHEL-40272]
- edk2-MdePkg-BaseRngLib-Add-a-smoketest-for-RDRAND-and-che.patch [RHEL-40270 RHEL-40272]
- edk2-SecurityPkg-RngDxe-add-rng-test.patch [RHEL-40270 RHEL-40272]
- edk2-OvmfPkg-wire-up-RngDxe.patch [RHEL-40270 RHEL-40272]
- edk2-CryptoPkg-Test-call-ProcessLibraryConstructorList.patch [RHEL-40270 RHEL-40272]
- edk2-MdePkg-X86UnitTestHost-set-rdrand-cpuid-bit.patch [RHEL-40270 RHEL-40272]
- Resolves: RHEL-40270
(CVE-2023-45237 edk2: Use of a Weak PseudoRandom Number Generator [rhel-9.4.z])
- Resolves: RHEL-40272
(CVE-2023-45236 edk2: Predictable TCP Initial Sequence Numbers [rhel-9.4.z])

[20231122-6.el9_4.1]
- edk2-EmbeddedPkg-Hob-Integer-Overflow-in-CreateHob.patch [RHEL-30156]
- edk2-StandaloneMmPkg-Hob-Integer-Overflow-in-CreateHob.patch [RHEL-30156]
- Resolves: RHEL-30156
(CVE-2022-36765 edk2: integer overflow in CreateHob() could lead to HOB OOB R/W [rhel-9.4.z])


Related CVEs


CVE-2022-36765
CVE-2023-45236
CVE-2023-45237

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) edk2-20231122-6.0.1.el9_4.2.src.rpm0fea8e85b2a6a444f817766e829aa1ed-ol9_aarch64_appstream
edk2-20231122-6.0.1.el9_4.2.src.rpm0fea8e85b2a6a444f817766e829aa1ed-ol9_aarch64_codeready_builder
edk2-aarch64-20231122-6.0.1.el9_4.2.noarch.rpm8df76425204c63b2ef1a875f574491e9-ol9_aarch64_appstream
edk2-ovmf-20231122-6.0.1.el9_4.2.noarch.rpm7ad084a32d943ad08eab4843343aae04-ol9_aarch64_appstream
edk2-tools-20231122-6.0.1.el9_4.2.aarch64.rpm87293a0f579633ffbd0adb67ec7da2f1-ol9_aarch64_codeready_builder
edk2-tools-doc-20231122-6.0.1.el9_4.2.noarch.rpmcc479642bfd398af8e2ece95536d3f68-ol9_aarch64_codeready_builder
Oracle Linux 9 (x86_64) edk2-20231122-6.0.1.el9_4.2.src.rpm0fea8e85b2a6a444f817766e829aa1ed-ol9_x86_64_appstream
edk2-20231122-6.0.1.el9_4.2.src.rpm0fea8e85b2a6a444f817766e829aa1ed-ol9_x86_64_codeready_builder
edk2-aarch64-20231122-6.0.1.el9_4.2.noarch.rpm8df76425204c63b2ef1a875f574491e9-ol9_x86_64_codeready_builder
edk2-ovmf-20231122-6.0.1.el9_4.2.noarch.rpm7ad084a32d943ad08eab4843343aae04-ol9_x86_64_appstream
edk2-tools-20231122-6.0.1.el9_4.2.x86_64.rpm27bfa6af9547919489a7388fea5007f8-ol9_x86_64_codeready_builder
edk2-tools-doc-20231122-6.0.1.el9_4.2.noarch.rpmcc479642bfd398af8e2ece95536d3f68-ol9_x86_64_codeready_builder


This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections:

software.hardware.complete