Package "edk2"

Name: edk2


This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • UEFI firmware for 64-bit x86 virtual machines
  • UEFI firmware for 64-bit ARM virtual machines
  • UEFI firmware for 32-bit ARM virtual machines

Latest version: 2020.11-4ubuntu0.1
Release: hirsute (21.04)
Level: updates
Repository: main


Other versions of "edk2" in Hirsute

Repository Area Version
base main 2020.11-4
base universe 2020.11-4
security main 2020.11-4ubuntu0.1
security universe 2020.11-4ubuntu0.1
updates universe 2020.11-4ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Version: 2020.11-4ubuntu0.1 2021-09-23 13:06:28 UTC

  edk2 (2020.11-4ubuntu0.1) hirsute-security; urgency=medium

  * SECURITY UPDATE: Insufficient input validation in MdeModulePkg
    - debian/patches/CVE-2019-11098-*.patch
    - CVE-2019-11098
  * SECURITY UPDATE: overflow in openssl EVP_DecryptUpdate
    - debian/patches/CVE-2021-23840.patch
    - CVE-2021-23840
  * SECURITY UPDATE: DoS via incorrect ASN.1 string termination in openssl
    - debian/patches/CVE-2021-3712-*.patch
    - CVE-2021-3712
  * SECURITY UPDATE: remote buffer overflow in IScsiHexToBin
    - debian/patches/CVE-2021-38575-*.patch
    - CVE-2021-38575

 -- Marc Deslauriers <email address hidden> Fri, 17 Sep 2021 11:03:13 -0400

CVE-2019-11098 Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of ser
CVE-2021-23840 Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is cl
CVE-2021-3712 Read buffer overruns processing ASN.1 strings
CVE-2021-38575 edk2: remote buffer overflow in IScsiHexToBin function in NetworkPkg/IScsiDxe

About   -   Send Feedback to @ubuntu_updates