RHSA-2023:4128: Important: edk2 security update
EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. Security Fix(es): openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) openssl: timing attack in RSA Decryption implementation (CVE-2022-4304) openssl: use-after-free following BIOnewNDEF (CVE-2023-0215) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/edk2to a version that resolves this vulnerability.Fixed in 20220126gitbb1bba3d77-2.el8_6.1 - Upgrade
Upgrade
redhat/edk2-ovmfto a version that resolves this vulnerability.Fixed in 20220126gitbb1bba3d77-2.el8_6.1 - Upgrade
Upgrade
redhat/edk2-aarch64to a version that resolves this vulnerability.Fixed in 20220126gitbb1bba3d77-2.el8_6.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:4128?
The severity of RHSA-2023:4128 is high.
Which software is affected by RHSA-2023:4128?
The Red Hat Enterprise Linux products listed in the description are affected by RHSA-2023:4128.
How do I fix RHSA-2023:4128?
To fix RHSA-2023:4128, update the affected edk2 packages to the specified version mentioned in the description.
Where can I find more information about RHSA-2023:4128?
You can find more information about RHSA-2023:4128 on the Red Hat Errata website.
What is the Common Weakness Enumeration (CWE) ID for RHSA-2023:4128?
The CWE ID for RHSA-2023:4128 is 416.