Debian Security Advisory
DLA-2645-1 edk2 -- LTS security update
- Date Reported:
- 29 Apr 2021
- Affected Packages:
- edk2
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 952926, Bug 968819, Bug 952934, Bug 977300.
In Mitre's CVE dictionary: CVE-2019-0161, CVE-2019-14558, CVE-2019-14559, CVE-2019-14562, CVE-2019-14563, CVE-2019-14575, CVE-2019-14584, CVE-2019-14586, CVE-2019-14587, CVE-2021-28210, CVE-2021-28211. - More information:
-
Several security vulnerabilities have been discovered in edk2, firmware for virtual machines. Integer and stack overflows and uncontrolled resource consumption may lead to a denial-of-service or in a worst case scenario, allow an authenticated local user to potentially enable escalation of privilege.
For Debian 9 stretch, these problems have been fixed in version 0~20161202.7bbe0b3e-1+deb9u2.
We recommend that you upgrade your edk2 packages.
For the detailed security status of edk2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/edk2
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS