Unchecked Return Value in edk2 - CVE-2019-14560
Published: November 24, 2023
Vulnerability identifier: #VU83486
CSH Severity: Low
CVSS v4 BT: 4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2019-14560
CWE-ID: CWE-252
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to an unchecked return value within the DxeImageVerificationHandler() function in SecurityPkg/Library/DxeImageVerificationLib/DxeImageVerificationLib.c. A local user can bypass the secure boot protection.
Affected software
edk2
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
edk2 (Red Hat package)
edk2-aarch64
edk2-ovmf
edk2-tools-doc
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
edk2 (Red Hat package)
edk2-aarch64
edk2-ovmf
edk2-tools-doc
How to mitigate CVE-2019-14560
Install updates from vendor's website.
edk2 - update to edk2-stable202305
edk2 (Red Hat package) - addressed in versions 20220126gitbb1bba3d77-4.el8_8.3, 20220126gitbb1bba3d77-6.el8
edk2-aarch64 - addressed in versions 20220126gitbb1bba3d77-5, 20220126gitbb1bba3d77-6.0.2
edk2-ovmf - addressed in versions 20220126gitbb1bba3d77-5, 20220126gitbb1bba3d77-6.0.2
edk2-tools-doc - addressed in versions 20220126gitbb1bba3d77-5, 20220126gitbb1bba3d77-6.0.2
edk2 (Red Hat package) - addressed in versions 20220126gitbb1bba3d77-4.el8_8.3, 20220126gitbb1bba3d77-6.el8
edk2-aarch64 - addressed in versions 20220126gitbb1bba3d77-5, 20220126gitbb1bba3d77-6.0.2
edk2-ovmf - addressed in versions 20220126gitbb1bba3d77-5, 20220126gitbb1bba3d77-6.0.2
edk2-tools-doc - addressed in versions 20220126gitbb1bba3d77-5, 20220126gitbb1bba3d77-6.0.2