]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
ovmf: fix CVE-2025-2295
authorHongxu Jia <hongxu.jia@windriver.com>
Mon, 7 Apr 2025 11:37:13 +0000 (19:37 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 10 Apr 2025 08:03:09 +0000 (09:03 +0100)
commit0f59dec939cf0d313b1b01b1e7bf10e059d9d0ac
treeae80c282a768a6e5ce651988fa18dd95881babfa
parent6e526327f5c9e739ac7981e4a43a4ce53a908945
ovmf: fix CVE-2025-2295

According to [1], EDK2 contains a vulnerability in BIOS where a user may
cause an Integer Overflow or Wraparound by network means. A successful
exploitation of this vulnerability may lead to denial of service.

Refer debian [2], backport a patch from edk2 [3] to fix CVE-2025-2295

[1] https://nvd.nist.gov/vuln/detail/CVE-2025-2295
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1100594
[3] https://github.com/tianocore/edk2/commit/17cdc512f02a2dfd1b9e24133da56fdda099abda

Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-core/ovmf/ovmf/CVE-2025-2295.patch [new file with mode: 0644]
meta/recipes-core/ovmf/ovmf_git.bb