Debian Security Advisory

DLA-2645-1 edk2 -- LTS security update

Date Reported:
29 Apr 2021
Affected Packages:
edk2
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 952926, Bug 968819, Bug 952934, Bug 977300.
In Mitre's CVE dictionary: CVE-2019-0161, CVE-2019-14558, CVE-2019-14559, CVE-2019-14562, CVE-2019-14563, CVE-2019-14575, CVE-2019-14584, CVE-2019-14586, CVE-2019-14587, CVE-2021-28210, CVE-2021-28211.
More information:

Several security vulnerabilities have been discovered in edk2, firmware for virtual machines. Integer and stack overflows and uncontrolled resource consumption may lead to a denial-of-service or in a worst case scenario, allow an authenticated local user to potentially enable escalation of privilege.

For Debian 9 stretch, these problems have been fixed in version 0~20161202.7bbe0b3e-1+deb9u2.

We recommend that you upgrade your edk2 packages.

For the detailed security status of edk2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/edk2

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS