flatcar / Flatcar

Flatcar project repository for issue tracking, project documentation, etc.
https://www.flatcar.org/
Apache License 2.0
693 stars 30 forks source link

update: edk2-ovmf-bin #1318

Open dongsupark opened 8 months ago

dongsupark commented 8 months ago

Name: edk2-ovmf-bin CVEs: CVE-2022-36763, CVE-2022-36764, CVE-2022-36765, CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237, CVE-2024-1298 CVSSs: 7.8, 7.8, 7.8, 6.5, 8.8, 6.5, 7.5, 7.5, 8.8, 8.8, 7.5, 7.5, 6.0 Action Needed: TBD for CVE-2023-*, update to >= 202405 for CVE-2024-1298

Summary:

Not critical, as edk2-ovmf-bin is only included in the Flatcar SDK.

refmap.gentoo:

tormath1 commented 8 months ago

Added: CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236 and CVE-2023-45237

dongsupark commented 3 months ago

Added CVE-2024-1298.