Uncontrolled Recursion in edk2 - CVE-2021-28210

 

Uncontrolled Recursion in edk2 - CVE-2021-28210

Published: April 8, 2022


Vulnerability identifier: #VU62014
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28210
CWE-ID: CWE-674
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to an unlimited recursion in DxeCore. A local user can execute arbitrary code on the target system.


Affected software

edk2
Avamar Data Store Gen5A
Integrated System for Microsoft Azure Stack Hub
MediaWiki
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Server Applications
openEuler
Ubuntu
ovmf (Ubuntu package)
qemu-efi (Ubuntu package)
qemu-efi-aarch64 (Ubuntu package)
qemu-efi-arm (Ubuntu package)
qemu-ovmf-x86_64
ovmf-tools
ovmf
qemu-uefi-aarch64
edk2
edk2-debuginfo
edk2-debugsource
edk2-devel
python3-edk2-devel
edk2-ovmf
edk2-aarch64
edk2-help
Dell EMC VxRail Appliance

How to mitigate CVE-2021-28210

Install updates from vendor's website.

edk2 - update to edk2-stable202011
MediaWiki - addressed in versions 1.35.6, 1.36.4, 1.37.2
ovmf (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
qemu-efi (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
qemu-efi-aarch64 (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
qemu-efi-arm (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.2, 2020.05-5ubuntu0.2
Dell EMC VxRail Appliance - update to 4.5.480
qemu-ovmf-x86_64 - addressed in versions 2015+git1462940744.321151f-19.23.1, 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
ovmf-tools - addressed in versions 2015+git1462940744.321151f-19.23.1, 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
ovmf - addressed in versions 2015+git1462940744.321151f-19.23.1, 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
qemu-uefi-aarch64 - addressed in versions 2017+git1510945757.b2662641d5-3.35.1, 2017+git1510945757.b2662641d5-5.43.1, 201911-7.11.1
Integrated System for Microsoft Azure Stack Hub - update to 2207
edk2 - update to 202002-4
edk2-debuginfo - update to 202002-4
edk2-debugsource - update to 202002-4
edk2-devel - update to 202002-4
python3-edk2-devel - update to 202002-4
edk2-ovmf - update to 202002-4
edk2-aarch64 - update to 202002-4
edk2-help - update to 202002-4

External References

Related Security Bulletins