Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: 7eff71fe690a0f5bc0be67b5b83f263d7892f9b6
      
https://github.com/tianocore/edk2/commit/7eff71fe690a0f5bc0be67b5b83f263d7892f9b6
  Author: Oliver Smith-Denny <o...@microsoft.com>
  Date:   2024-11-26 (Tue, 26 Nov 2024)

  Changed paths:
    M SecurityPkg/DeviceSecurity/SpdmLib/libspdm

  Log Message:
  -----------
  SecurityPkg: Update libspdm

This patch updates libspdm to pull in various bug fixes,
but primarily commit ca4854be3325bd8fc7f2c714574d17aac2d4e13b
which updates libspdm's MbedTLS submodule to v3.6.2, fixing
CVE https://nvd.nist.gov/vuln/detail/CVE-2023-37920 there.
This CVE does not affect libspdm or edk2, but automatic
CVE scanning tools see the bad version of the certifi
pip module in the edk2/libspdm code trees and flag these
projects as failing.
libspdm has been updated to pull in the newer MbedTLS that
fixes this issue and this patch updates edk2 to pull in
the newer libspdm.

Signed-off-by: Oliver Smith-Denny <o...@linux.microsoft.com>



To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
edk2-commits@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to