RHSA-2023:4128: Important: edk2 security update
EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. Security Fix(es): openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) openssl: timing attack in RSA Decryption implementation (CVE-2022-4304) openssl: use-after-free following BIO_new_NDEF (CVE-2023-0215) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:4128?
The severity of RHSA-2023:4128 is high.
Which software is affected by RHSA-2023:4128?
The Red Hat Enterprise Linux products listed in the description are affected by RHSA-2023:4128.
How do I fix RHSA-2023:4128?
To fix RHSA-2023:4128, update the affected edk2 packages to the specified version mentioned in the description.
Where can I find more information about RHSA-2023:4128?
You can find more information about RHSA-2023:4128 on the Red Hat Errata website.
What is the Common Weakness Enumeration (CWE) ID for RHSA-2023:4128?
The CWE ID for RHSA-2023:4128 is 416.