Heap-based buffer overflow in edk2 - CVE-2021-28211
Published: June 30, 2021
Vulnerability identifier: #VU54481
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28211
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the LzmaUefiDecompressGetInfo() function. A local user can run a specially crafted program to trigger a heap-based buffer overflow and execute arbitrary code with elevated privileges.
Affected software
edk2
Avamar Data Store Gen5A
Integrated System for Microsoft Azure Stack Hub
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Server Applications
openEuler
Ubuntu
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
ovmf (Ubuntu package)
qemu-efi-arm (Ubuntu package)
qemu-efi (Ubuntu package)
qemu-efi-aarch64 (Ubuntu package)
qemu-ovmf-x86_64
ovmf-tools
ovmf
qemu-uefi-aarch64
edk2-debuginfo
python3-edk2-devel
edk2-help
edk2-aarch64
edk2-ovmf
edk2-debugsource
edk2-devel
edk2
edk2 (Red hat package)
OpenShift Virtualization
Dell EMC VxRail Appliance
Avamar Data Store Gen5A
Integrated System for Microsoft Azure Stack Hub
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Server Applications
openEuler
Ubuntu
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
ovmf (Ubuntu package)
qemu-efi-arm (Ubuntu package)
qemu-efi (Ubuntu package)
qemu-efi-aarch64 (Ubuntu package)
qemu-ovmf-x86_64
ovmf-tools
ovmf
qemu-uefi-aarch64
edk2-debuginfo
python3-edk2-devel
edk2-help
edk2-aarch64
edk2-ovmf
edk2-debugsource
edk2-devel
edk2
edk2 (Red hat package)
OpenShift Virtualization
Dell EMC VxRail Appliance
How to mitigate CVE-2021-28211
Install updates from vendor's website.
edk2 - update to edk2-stable202011
ovmf (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
qemu-efi-arm (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
qemu-efi (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
qemu-efi-aarch64 (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
Dell EMC VxRail Appliance - update to 4.5.480
qemu-ovmf-x86_64 - addressed in versions 2015+git1462940744.321151f-19.23.1, 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
ovmf-tools - addressed in versions 2015+git1462940744.321151f-19.23.1, 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
ovmf - addressed in versions 2015+git1462940744.321151f-19.23.1, 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
qemu-uefi-aarch64 - addressed in versions 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
Integrated System for Microsoft Azure Stack Hub - update to 2207
edk2-debuginfo - update to 202002-5
python3-edk2-devel - update to 202002-5
edk2-help - update to 202002-5
edk2-aarch64 - update to 202002-5
edk2-ovmf - update to 202002-5
edk2-debugsource - update to 202002-5
edk2-devel - update to 202002-5
edk2 - update to 202002-5
edk2-aarch64 - update to 20200602gitca407c7246bf-4
edk2-ovmf - update to 20200602gitca407c7246bf-4
edk2 (Red hat package) - update to 20200602gitca407c7246bf-4.el8_4.1
ovmf (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
qemu-efi-arm (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
qemu-efi (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
qemu-efi-aarch64 (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
Dell EMC VxRail Appliance - update to 4.5.480
qemu-ovmf-x86_64 - addressed in versions 2015+git1462940744.321151f-19.23.1, 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
ovmf-tools - addressed in versions 2015+git1462940744.321151f-19.23.1, 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
ovmf - addressed in versions 2015+git1462940744.321151f-19.23.1, 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
qemu-uefi-aarch64 - addressed in versions 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
Integrated System for Microsoft Azure Stack Hub - update to 2207
edk2-debuginfo - update to 202002-5
python3-edk2-devel - update to 202002-5
edk2-help - update to 202002-5
edk2-aarch64 - update to 202002-5
edk2-ovmf - update to 202002-5
edk2-debugsource - update to 202002-5
edk2-devel - update to 202002-5
edk2 - update to 202002-5
edk2-aarch64 - update to 20200602gitca407c7246bf-4
edk2-ovmf - update to 20200602gitca407c7246bf-4
edk2 (Red hat package) - update to 20200602gitca407c7246bf-4.el8_4.1
External References
Related Security Bulletins
- Privilege escalation in Tianocore EDK II
- Red Hat Enterprise Linux 8 update for edk2
- Ubuntu update for edk2
- Multiple vulnerabilities in Dell VxRail
- Multiple vulnerabilities in Dell Avamar Data Store Gen5A
- Multiple vulnerabilities in Dell Integrated System for Microsoft Azure Stack Hub
- SUSE update for ovmf
- SUSE update for ovmf
- SUSE update for ovmf
- SUSE update for ovmf
- openEuler update for edk2
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Anolis OS update for edk2