Input validation error in edk2 - CVE-2019-11098

 

Input validation error in edk2 - CVE-2019-11098

Published: January 2, 2023


Vulnerability identifier: #VU70612
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11098
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in MdeModulePkg. An attacker with physical access to the affected system can execute arbitrary code.


Affected software

edk2
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
openEuler
Ubuntu
ovmf (Ubuntu package)
qemu-efi-aarch64 (Ubuntu package)
qemu-efi (Ubuntu package)
qemu-efi-arm (Ubuntu package)
ovmf-ia32 (Ubuntu package)
ovmf
qemu-ovmf-x86_64
qemu-uefi-aarch64
ovmf-tools
edk2-ovmf
python3-edk2-devel
edk2-aarch64
edk2-help
edk2-debugsource
edk2-debuginfo
edk2-devel
edk2

How to mitigate CVE-2019-11098

Install updates from vendor's website.

ovmf (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.3, 2020.11-4ubuntu0.1
qemu-efi-aarch64 (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.3, 2020.11-4ubuntu0.1
qemu-efi (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.3, 2020.11-4ubuntu0.1
qemu-efi-arm (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.3, 2020.11-4ubuntu0.1
ovmf-ia32 (Ubuntu package) - update to 2020.11-4ubuntu0.1
ovmf - addressed in versions 201911-150200.7.24.1, 202008-150300.10.17.1
qemu-ovmf-x86_64 - addressed in versions 201911-150200.7.24.1, 202008-150300.10.17.1
qemu-uefi-aarch64 - addressed in versions 201911-150200.7.24.1, 202008-150300.10.17.1
ovmf-tools - addressed in versions 201911-150200.7.24.1, 202008-150300.10.17.1
edk2-ovmf - addressed in versions 202002-10, 202011-6
python3-edk2-devel - addressed in versions 202002-10, 202011-6
edk2-aarch64 - addressed in versions 202002-10, 202011-6
edk2-help - addressed in versions 202002-10, 202011-6
edk2-debugsource - addressed in versions 202002-10, 202011-6
edk2-debuginfo - addressed in versions 202002-10, 202011-6
edk2-devel - addressed in versions 202002-10, 202011-6
edk2 - addressed in versions 202002-10, 202011-6

External References

Related Security Bulletins