RHSA-2024:1063: Important: edk2 security update
EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. Security Fix(es): edk2: Buffer overflow in the DHCPv6 client via a long Server ID option (CVE-2023-45230) edk2: Buffer overflow when processing DNS Servers option in a DHCPv6 Advertise message (CVE-2023-45234) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/edk2to a version that resolves this vulnerability.Fixed in 20220126gitbb1bba3d77-6.el8_9.6 - Upgrade
Upgrade
redhat/edk2-ovmfto a version that resolves this vulnerability.Fixed in 20220126gitbb1bba3d77-6.el8_9.6 - Upgrade
Upgrade
redhat/edk2-aarch64to a version that resolves this vulnerability.Fixed in 20220126gitbb1bba3d77-6.el8_9.6
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1063?
The severity of RHSA-2024:1063 is classified as high due to the buffer overflow vulnerability.
How do I fix RHSA-2024:1063?
To fix RHSA-2024:1063, you need to update to the package version 20220126gitbb1bba3d77-6.el8_9.6.
What vulnerability is addressed in RHSA-2024:1063?
RHSA-2024:1063 addresses a buffer overflow vulnerability in the DHCPv6 client identified by CVE-2023-45230.
Which products are affected by RHSA-2024:1063?
RHSA-2024:1063 affects Red Hat Enterprise Linux for x86_64, ARM 64, and specific edk2 packages.
Is RHSA-2024:1063 related to virtual machine security?
Yes, RHSA-2024:1063 is related to UEFI support in virtual machines through the EDK project.