RHSA-2023:4252: Important: edk2 security update
EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. Security Fix(es): openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/edk2to a version that resolves this vulnerability.Fixed in 20200602gitca407c7246bf-4.el8_4.3 - Upgrade
Upgrade
redhat/edk2-ovmfto a version that resolves this vulnerability.Fixed in 20200602gitca407c7246bf-4.el8_4.3 - Upgrade
Upgrade
redhat/edk2-aarch64to a version that resolves this vulnerability.Fixed in 20200602gitca407c7246bf-4.el8_4.3 - Upgrade
Upgrade
opensslto a version that resolves this vulnerability.Patch CVE-2023-0286
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:4252?
The severity of RHSA-2023:4252 is high with a severity value of 7.
What is the affected software for RHSA-2023:4252?
The affected software for RHSA-2023:4252 includes Red Hat Enterprise Linux Server - TUS, Red Hat Enterprise Linux Server - AUS, Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions, edk2 package, and edk2-ovmf package.
Where can I find more information about RHSA-2023:4252?
You can find more information about RHSA-2023:4252 at these references: [Link 1](https://access.redhat.com/errata/RHSA-2023:4252), [Link 2](https://bugzilla.redhat.com/show_bug.cgi?id=2164440), [Link 3](https://access.redhat.com/security/updates/classification/#important).
How do I fix RHSA-2023:4252?
To fix RHSA-2023:4252, you need to update the affected software packages to version 20200602gitca407c7246bf-4.el8_4.3 or later.
What is the description of RHSA-2023:4252?
The description of RHSA-2023:4252 is "Important: edk2 security update".