ALT-BU-2019-3841-1
Branch p9 update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2018-12182
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
- 107648
- 107648
- https://edk2-docs.gitbooks.io/security-advisory/content/sw-smi-confused-deputy-smramsavestate_c.html
- https://edk2-docs.gitbooks.io/security-advisory/content/sw-smi-confused-deputy-smramsavestate_c.html
- FEDORA-2019-d47a9d4b8b
- FEDORA-2019-d47a9d4b8b
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_us
Package u-boot-tools updated to version 2019.07-alt1 for branch p9 in task 235355.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2019-11059
Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.
Modified: 2024-11-21
CVE-2019-11690
gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device.
Modified: 2024-11-21
CVE-2019-13103
A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data.
- https://cert-portal.siemens.com/productcert/pdf/ssa-618620.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-618620.pdf
- https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75
- https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75
- https://github.com/u-boot/u-boot/commits/master
- https://github.com/u-boot/u-boot/commits/master
- https://lists.denx.de/pipermail/u-boot/2019-July/375512.html
- https://lists.denx.de/pipermail/u-boot/2019-July/375512.html