edk2: improper input validation leads to memory corruption when loading PE sections
Published Feb 28, 2023
No CVSS score
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 8
edk2
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat has evaluated this issue and determined that it does not meet the criteria to be classified as a security vulnerability. This assessment is based on the issue not posing a significant security risk, being a result of misconfiguration or usage error, or falling outside the scope of security considerations. As such, this CVE has been marked as "Rejected" in alignment with Red Hat's vulnerability management policies. If you have additional information or concerns regarding this determination, please contact Red Hat Product Security for further clarification.
References (5)
- https://access.redhat.com/security/cve/CVE-2019-14561 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1758595 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5722 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14561
- https://www.cve.org/CVERecord?id=CVE-2019-14561
Change history (0)
No recorded changes yet.
CISA Vulnrichment
No data
GitHub
No data