UbuntuUpdates.org

Package "edk2"

Name: edk2

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • UEFI firmware for 64-bit x86 virtual machines
  • UEFI firmware for 64-bit ARM virtual machines
  • UEFI firmware for 32-bit ARM virtual machines

Latest version: 2020.05-5ubuntu0.2
Release: groovy (20.10)
Level: updates
Repository: main

Links



Other versions of "edk2" in Groovy

Repository Area Version
base universe 2020.05-5
base main 2020.05-5
security main 2020.05-5ubuntu0.2
security universe 2020.05-5ubuntu0.2
updates universe 2020.05-5ubuntu0.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2020.05-5ubuntu0.2 2021-04-20 20:06:30 UTC

  edk2 (2020.05-5ubuntu0.2) groovy-security; urgency=medium

  * SECURITY UPDATE: unlimited FV recursion
    - debian/patches/CVE-2021-28210-1.patch: assert SectionInstance
      invariant in FindChildNode() in
      MdeModulePkg/Core/Dxe/SectionExtraction/CoreSectionExtraction.c.
    - debian/patches/CVE-2021-28210-2.patch: limit FwVol encapsulation
      section recursion in MdeModulePkg/Core/Dxe/DxeMain.inf,
      MdeModulePkg/Core/Dxe/SectionExtraction/CoreSectionExtraction.c,
      MdeModulePkg/MdeModulePkg.dec, MdeModulePkg/MdeModulePkg.uni.
    - CVE-2021-28210
  * SECURITY UPDATE: possible heap corruption in LzmaUefiDecompressGetInfo
    - debian/patches/CVE-2021-28211.patch: catch 4GB+ uncompressed
      buffer sizes in
      MdeModulePkg/Library/LzmaCustomDecompressLib/LzmaDecompress.c,
      MdeModulePkg/Library/LzmaCustomDecompressLib/LzmaDecompressLibInternal.h.
    - CVE-2021-28211

 -- Marc Deslauriers <email address hidden> Mon, 12 Apr 2021 08:12:17 -0400

Source diff to previous version
CVE-2021-28210 unlimited FV recursion, round 2
CVE-2021-28211 possible heap corruption with LzmaUefiDecompressGetInfo

Version: 2020.05-5ubuntu0.1 2021-01-07 16:07:16 UTC

  edk2 (2020.05-5ubuntu0.1) groovy-security; urgency=medium

  * CryptoPkg/BaseCryptLib: fix NULL dereference (CVE-2019-14584)

 -- dann frazier <email address hidden> Tue, 05 Jan 2021 16:31:45 -0700




About   -   Send Feedback to @ubuntu_updates