Information on source package edk2

Available versions

ReleaseVersion
stretch0~20161202.7bbe0b3e-1+deb9u1
stretch (security)0~20161202.7bbe0b3e-1+deb9u2
buster0~20181115.85588389-3+deb10u3
bullseye2020.11-2
sid2020.11-5

Open issues

BugstretchbusterbullseyesidDescription
CVE-2021-28213vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerableExample EDK2 encrypted private key in the IpSecDxe.efi present potenti ...
CVE-2021-28211fixedvulnerable (no DSA)fixedfixedA heap overflow in LzmaUefiDecompressGetInfo function in EDK II. ...
CVE-2021-28210fixedvulnerable (no DSA)fixedfixedAn unlimited recursion in DxeCore in EDK II. ...
CVE-2019-14560vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerableGetEfiGlobalVariable2() return value not checked
CVE-2019-11098vulnerable (no DSA)vulnerable (no DSA)vulnerablefixedInsufficient input validation in MdeModulePkg in EDKII may allow an un ...
CVE-2018-12183vulnerable (no DSA, ignored)fixedfixedfixedStack overflow in DxeCore for EDK II may allow an unauthenticated user ...

Open unimportant issues

BugstretchbusterbullseyesidDescription
CVE-2019-14553vulnerablevulnerablefixedfixedImproper authentication in EDK II may allow a privileged user to poten ...
CVE-2019-0160vulnerablefixedfixedfixedBuffer overflow in system firmware for EDK II may allow unauthenticate ...
CVE-2018-12182vulnerablevulnerablefixedfixedInsufficient memory write check in SMM service for EDK II may allow an ...
CVE-2018-12179vulnerablevulnerablefixedfixedImproper configuration in system firmware for EDK II may allow unauthe ...
CVE-2014-4860vulnerablevulnerablefixedfixedMultiple integer overflows in the Pre-EFI Initialization (PEI) boot ph ...
CVE-2014-4859vulnerablevulnerablefixedfixedInteger overflow in the Drive Execution Environment (DXE) phase in the ...

Resolved issues

BugDescription
CVE-2019-14587Logic issue EDK II may allow an unauthenticated user to potentially en ...
CVE-2019-14586Use after free vulnerability in EDK II may allow an authenticated user ...
CVE-2019-14584Null pointer dereference in Tianocore EDK2 may allow an authenticated ...
CVE-2019-14575Logic issue in DxeImageVerificationHandler() for EDK II may allow an a ...
CVE-2019-14563Integer truncation in EDK II may allow an authenticated user to potent ...
CVE-2019-14562Integer overflow in DxeImageVerificationHandler() EDK II may allow an ...
CVE-2019-14559Uncontrolled resource consumption in EDK II may allow an unauthenticat ...
CVE-2019-14558Insufficient control flow management in BIOS firmware for 8th, 9th, 10 ...
CVE-2019-0161Stack overflow in XHCI for EDK II may allow an unauthenticated user to ...
CVE-2018-12181Stack overflow in corrupted bmp for EDK II may allow unprivileged user ...
CVE-2018-12180Buffer overflow in BlockIo service for EDK II may allow an unauthentic ...
CVE-2018-12178Buffer overflow in network stack for EDK II may allow unprivileged use ...

Security announcements

DSA / DLADescription
DLA-2645-1edk2 - security update

Search for package or bug name: Reporting problems