Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

SUSE: 2021:2117-1 Important: Ovmf Buffer Overflow and Heap Corruption

suse
Calendar Grey June 22, 2021
Scroller Suse
SUSE Security Patch for ovmf addresses critical vulnerabilities such as buffer overflow, heap corruption, and infinite recursion. Ensure your system is protected!
An update that solves three vulnerabilities and has one errata is now available

Summary

This update for ovmf fixes the following issues: - Fixed a possible buffer overflow in IScsiDxe (bsc#1186151) - CVE-2021-28211: ovmf: edk2: possible heap corruption with LzmaUefiDecompressGetInfo (bsc#1183578) - CVE-2021-28210: ovmf: unlimited FV recursion, round 2 (bsc#1183579) - CVE-2019-14584: ovmf,shim: NULL pointer dereference in AuthenticodeVerify() (bsc#1177789) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-2117=1 Package List: - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): ovmf-2015+git1462940744.321151f-19.23.1

References

#1177789 #1183578 #1183579 #1186151

Cross- CVE-2019-14584 CVE-2021-28210 CVE-2021-28211

CVSS scores:

CVE-2019-14584 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-14584 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE-2021-28210 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

CVE-2021-28211 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Server 12-SP2-BCL

https://www.suse.com/security/cve/CVE-2019-14584.html

https://www.suse.com/security/cve/CVE-2021-28210.html

https://www.suse.com/security/cve/CVE-2021-28211.html

https://bugzilla.suse.com/1177789

https://bugzilla.suse.com/1183578

https://bugzilla.suse.com/1183579

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:2117-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.