USN-4923-1: EDK II vulnerabilities
Laszlo Ersek discovered that EDK II incorrectly handled recursion. A remote attacker could possibly use this issue to cause EDK II to consume resources, leading to a denial of service. (CVE-2021-28210) Satoshi Tanda discovered that EDK II incorrectly handled decompressing certain images. A remote attacker could use this issue to cause EDK II to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-28211)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-4923-1?
The USN-4923-1 vulnerability is considered to allow for potential denial of service.
How do I fix USN-4923-1?
To fix USN-4923-1, update the affected packages to the recommended versions provided by Ubuntu.
What software is affected by USN-4923-1?
USN-4923-1 affects the ovmf and qemu-efi packages on Ubuntu versions 20.04 and 20.10.
Can USN-4923-1 be exploited remotely?
Yes, USN-4923-1 can potentially be exploited by a remote attacker to consume system resources.
What are the CVE identifiers associated with USN-4923-1?
USN-4923-1 is associated with CVE-2021-28210 and CVE-2021-28211.