RHSA-2023:6330MediumCVSS 6.5

Red Hat Security Advisory: edk2 security, bug fix, and enhancement update

Published
November 7, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

CVE-2019-14560 · pendingCVE-2023-2650

📋 Description

CVE-2019-14560 — edk2: Function GetEfiGlobalVariable2() return value not checked in DxeImageVerificationHandler() CVE-2023-2650 — openssl: Possible DoS translating ASN.1 object identifiers

🎯 Affected products14

  • Red Hat CodeReady Linux Builder (v. 9)
  • Red Hat Enterprise Linux AppStream (v. 9)
  • edk2-0:20230524-3.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • edk2-aarch64-0:20230524-3.el9.noarch as a component of Red Hat CodeReady Linux Builder (v. 9)
  • edk2-aarch64-0:20230524-3.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • edk2-debugsource-0:20230524-3.el9.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • edk2-debugsource-0:20230524-3.el9.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • edk2-ovmf-0:20230524-3.el9.noarch as a component of Red Hat CodeReady Linux Builder (v. 9)
  • edk2-ovmf-0:20230524-3.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • edk2-tools-0:20230524-3.el9.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • edk2-tools-0:20230524-3.el9.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • edk2-tools-debuginfo-0:20230524-3.el9.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • edk2-tools-debuginfo-0:20230524-3.el9.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 9)
  • edk2-tools-doc-0:20230524-3.el9.noarch as a component of Red Hat CodeReady Linux Builder (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (15)