rpm package
suse/ovmf&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
pkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSS
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-38578 | Hig | 7.4 | < 201911-150200.7.27.1 | 201911-150200.7.27.1 | Mar 3, 2022 | Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. | |
| CVE-2019-11098 | Med | 6.8 | < 201911-150200.7.24.1 | 201911-150200.7.24.1 | Jul 14, 2021 | Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access. |
- affected < 201911-150200.7.27.1fixed 201911-150200.7.27.1
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
- affected < 201911-150200.7.24.1fixed 201911-150200.7.24.1
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.