EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications.
Security Fix(es):
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
(CVE-2022-36763)
{ "severity": "High" }
{ "src": [ "edk2-202002-23.oe2003sp4.src.rpm" ], "aarch64": [ "edk2-debuginfo-202002-23.oe2003sp4.aarch64.rpm", "edk2-debugsource-202002-23.oe2003sp4.aarch64.rpm", "edk2-devel-202002-23.oe2003sp4.aarch64.rpm" ], "x86_64": [ "edk2-debuginfo-202002-23.oe2003sp4.x86_64.rpm", "edk2-debugsource-202002-23.oe2003sp4.x86_64.rpm", "edk2-devel-202002-23.oe2003sp4.x86_64.rpm" ], "noarch": [ "edk2-aarch64-202002-23.oe2003sp4.noarch.rpm", "edk2-help-202002-23.oe2003sp4.noarch.rpm", "edk2-ovmf-202002-23.oe2003sp4.noarch.rpm", "python3-edk2-devel-202002-23.oe2003sp4.noarch.rpm" ] }