MEDIUM
edk2: Function GetEfiGlobalVariable2() return value not checked in DxeImageVerificationHandler()
Published Feb 28, 2023
6.1
MEDIUMCVSS 3.1
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 8
edk2-0:20220126gitbb1bba3d77-6.el8
Fixed · RHSA-2023:6919
Red Hat Enterprise Linux 8.6 Extended Update Support
edk2-0:20220126gitbb1bba3d77-2.el8_6.2
Fixed · RHSA-2024:0408
Red Hat Enterprise Linux 8.8 Extended Update Support
edk2-0:20220126gitbb1bba3d77-4.el8_8.3
Fixed · RHSA-2024:1415
Red Hat Enterprise Linux 9
edk2-0:20230524-3.el9
Fixed · RHSA-2023:6330
Red Hat Enterprise Linux 7
ovmf
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | edk2-0:20220126gitbb1bba3d77-6.el8 | Fixed | RHSA-2023:6919 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | edk2-0:20220126gitbb1bba3d77-2.el8_6.2 | Fixed | RHSA-2024:0408 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | edk2-0:20220126gitbb1bba3d77-4.el8_8.3 | Fixed | RHSA-2024:1415 |
| Red Hat Enterprise Linux 9 | edk2-0:20230524-3.el9 | Fixed | RHSA-2023:6330 |
| Red Hat Enterprise Linux 7 | ovmf | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2019-14560 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1858038 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5721 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14560
- https://security.archlinux.org/CVE-2019-14560
- https://www.cve.org/CVERecord?id=CVE-2019-14560
- https://www.suse.com/security/cve/CVE-2019-14560.html
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Feb 28, 2023
Updated n/a
Reserved n/a
Link CVE-2019-14560
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-5721 Assigner intel
Published n/a
Updated Feb 28, 2023
Exploited since n/a
Link EUVD-2019-5721