Security update for ovmf
This update for ovmf fixes the following issues: - Fixed a possible buffer overflow in IScsiDxe (bsc#1186151) - CVE-2021-28211: ovmf: edk2: possible heap corruption with LzmaUefiDecompressGetInfo (bsc#1183578) - CVE-2021-28210: ovmf: unlimited FV recursion, round 2 (bsc#1183579) - CVE-2019-14584: ovmf,shim: NULL pointer dereference in AuthenticodeVerify() (bsc#1177789)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ovmf fixes the following issues: - Fixed a possible buffer overflow in IScsiDxe (bsc#1186151) - CVE-2021-28211: ovmf: edk2: possible heap corruption with LzmaUefiDecompressGetInfo (bsc#1183578) - CVE-2021-28210: ovmf: unlimited FV recursion, round 2 (bsc#1183579) - CVE-2019-14584: ovmf,shim: NULL pointer dereference in AuthenticodeVerify() (bsc#1177789)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1177789
- https://bugzilla.suse.com/1183578
- https://bugzilla.suse.com/1183579
- https://bugzilla.suse.com/1186151
- https://www.suse.com/security/cve/CVE-2019-14584
- https://www.suse.com/security/cve/CVE-2021-28210
- https://www.suse.com/security/cve/CVE-2021-28211
- https://www.suse.com/support/update/announcement/2021/suse-su-20212117-1/