[ALSA-2024:9088] Moderate: edk2 security update
Type:
security
Severity:
moderate
Release date:
2024-11-18
Description:
EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. Security Fix(es): * mysql: openssl: POLY1305 MAC implementation corrupts vector registers on PowerPC (CVE-2023-6129) * openssl: Excessive time spent checking invalid RSA public keys (CVE-2023-6237) * openssl: denial of service via null dereference (CVE-2024-0727) * edk2: Temporary DoS vulnerability (CVE-2024-1298) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 edk2-tools-20240524-6.el9_5.aarch64.rpm be7947a173399935f14c69efd38bea6d90835a5994d4a75f42479ceb929107af
noarch edk2-aarch64-20240524-6.el9_5.noarch.rpm 0d9f83e534d3284e489bcfefea1d4408a20de4e7e09474f1f0ed1e86c95b7a22
noarch edk2-ovmf-20240524-6.el9_5.noarch.rpm 3528b27d7d11bfda697bf5473dd8035de0ba56571ec5a5d94fd68b6948e6a27c
noarch edk2-tools-doc-20240524-6.el9_5.noarch.rpm 4abac5ddb9cf5e935717a02dfcab6de42d97baf7fe07f016bd130036a1619678
x86_64 edk2-tools-20240524-6.el9_5.x86_64.rpm 336dcdd44c07dd10249e73578b32ad82cde32cf38181428de88e9028a5941b53
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.