RHSA-2026:18465HighCVSS 8.2
Red Hat Security Advisory: edk2 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-2296 — edk2: EDK2: Improper Input Validation allows arbitrary command execution
🎯 Affected products14
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- edk2-0:20251114-5.el10_2.src as a component of Red Hat Enterprise Linux AppStream (v. 10)
- edk2-aarch64-0:20251114-5.el10_2.noarch as a component of Red Hat Enterprise Linux AppStream (v. 10)
- edk2-aarch64-0:20251114-5.el10_2.noarch as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- edk2-debugsource-0:20251114-5.el10_2.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- edk2-debugsource-0:20251114-5.el10_2.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- edk2-ovmf-0:20251114-5.el10_2.noarch as a component of Red Hat Enterprise Linux AppStream (v. 10)
- edk2-ovmf-0:20251114-5.el10_2.noarch as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- edk2-tools-0:20251114-5.el10_2.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- edk2-tools-0:20251114-5.el10_2.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- edk2-tools-debuginfo-0:20251114-5.el10_2.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- edk2-tools-debuginfo-0:20251114-5.el10_2.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- edk2-tools-doc-0:20251114-5.el10_2.noarch as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce the risk by disabling direct-boot mode, ensuring all bootable kernels are signed and present in the Secure Boot DB, and restricting privileged access to prevent attackers from introducing unsigned payloads.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:18465
- externalhttps://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/10.2_release_notes/index
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2420637
- externalhttps://issues.redhat.com/browse/RHEL-112106
- externalhttps://issues.redhat.com/browse/RHEL-116433
- externalhttps://issues.redhat.com/browse/RHEL-118386
- externalhttps://issues.redhat.com/browse/RHEL-138335
- externalhttps://issues.redhat.com/browse/RHEL-147785
- externalhttps://issues.redhat.com/browse/RHEL-150696
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_18465.json