Bug#1061256: edk2: CVE-2023-45229 CVE-2023-45230 CVE-2023-45231 CVE-2023-45232 CVE-2023-45233 CVE-2023-45234 CVE-2023-45235 CVE-2023-45236 CVE-2023-45237

2024-02-12 Thread dann frazier
On Sun, Feb 11, 2024 at 08:46:32PM +0100, Salvatore Bonaccorso wrote: > Does this split look good to you? Yes, thank you! -dann

Bug#1061256: edk2: CVE-2023-45229 CVE-2023-45230 CVE-2023-45231 CVE-2023-45232 CVE-2023-45233 CVE-2023-45234 CVE-2023-45235 CVE-2023-45236 CVE-2023-45237

2024-02-11 Thread Salvatore Bonaccorso
Control: clone 1061256 -1 -2 Control: retitle 1061256 edk2: CVE-2023-45229 CVE-2023-45230 CVE-2023-45231 CVE-2023-45232 CVE-2023-45233 CVE-2023-45234 CVE-2023-45235 Conytol: retitle -1 edk2: CVE-2023-45236 Control: retitle -2 edk2: CVE-2023-45237 Control: fixed 1061256 2023.11-6 Hi Dann, On

Bug#1061256: edk2: CVE-2023-45229 CVE-2023-45230 CVE-2023-45231 CVE-2023-45232 CVE-2023-45233 CVE-2023-45234 CVE-2023-45235 CVE-2023-45236 CVE-2023-45237

2024-02-10 Thread dann frazier
Thanks Salvatore. The first 7 are now fixed upstream, so I'm preparing an upload for those. Fixes for CVE-2023-45236 and CVE-2023-45237 are still in the works. Should we split those into separate bugs? -dann

Bug#1061256: edk2: CVE-2023-45229 CVE-2023-45230 CVE-2023-45231 CVE-2023-45232 CVE-2023-45233 CVE-2023-45234 CVE-2023-45235 CVE-2023-45236 CVE-2023-45237

2024-01-21 Thread Salvatore Bonaccorso
Source: edk2 Version: 2023.11-5 Severity: important X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for edk2. CVE-2023-45229[0]: | EDK2's Network Package is susceptible to an out-of-bounds read | vulnerability when processing the IA_NA or