QID 357224
Date Published: 2024-02-20
QID 357224: Amazon Linux Security Advisory for edk2 : ALAS2-2024-2465
Edk2 is susceptible to a vulnerability in the tcg2measuregpttable() function, allowing a user to trigger a heap buffer overflow via a local network.
Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. (
( CVE-2022-36763) edk2 is susceptible to a vulnerability in the tcg2measurepeimage() function, allowing a user to trigger a heap buffer overflow via a local network.
( CVE-2022-36764)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2-2024-2465 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2-2024-2465 -
alas.aws.amazon.com/AL2/ALAS-2024-2465.html
CVEs related to QID 357224
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2024-2465 | amazon linux 2 |
|