Use-after-free in OpenSSL - CVE-2024-4741

 

Use-after-free in OpenSSL - CVE-2024-4741

Published: May 29, 2024 / Updated: February 5, 2025


Vulnerability identifier: #VU89861
CSH Severity: Medium
CVSS v4 BT: 4.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-4741
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error within the SSL_free_buffers() function. A remote attacker can trigger a use-after-free error and perform a denial of service (DoS) attack.

Note, the vulnerability affects only applications that call the vulnerable function.


Affected software

OpenSSL
Oracle Solaris
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
IBM i
IBM AIX
Anolis OS
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Live Patching
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
Legacy Module
Development Tools Module
openSUSE Leap
openEuler
Ubuntu
Junos OS
IBM Concert Software
EasyApache
IBM Rational ClearQuest
IBM Automation Decision Services
Service Interconnect
Data Lakehouse
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Control
OpenShift Logging
Dell Secure Connect Gateway
IBM Rational Build Forge
IBM Rational ClearCase
IBM QRadar WinCollect Agent
Voice Gateway
Rapid Infrastructure Automation
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
Oracle Secure Backup
HP-UX OpenSSL
Aruba Networking Fabric Composer
Guardium Data Protection
EMC Cloud Tiering Appliance
CloudBoost Virtual Appliance
Robotic Process Automation for Cloud Pak
IBM VIOS
SecurityCenter
IBM Storage Scale System
Serv-U FTP Server
LANTIME Operating System Firmware (LTOS)
PowerProtect Cyber Recovery
Inspiron 24 5430 All-in-One
Inspiron 27 7730 All-in-One
Inspiron 16 7640 2-in-1
Alienware m16 R2
Latitude 3450
Latitude 3550
Precision 3280 CFF
Inspiron 14 7440 2-in-1
Inspiron 14 5440
Vostro 14 3440
Precision 3680 Tower
Inspiron 3030S
Inspiron 3030
Vostro 3030S
Vostro 3030
Inspiron 14 Plus 7440
Inspiron 16 Plus 7640
OptiPlex AIO 7420
OptiPlex 5055 A-Serial
OptiPlex 5055 Ryzen APU
OptiPlex 5055 Ryzen CPU
Inspiron 27 7720 All-in-One
Inspiron 24 5420 All-in-One
Latitude 5495
Inspiron 14 5430
Inspiron 14 7430 2-in-1
Inspiron 16 7630 2-in-1
Vostro 16 5630
Inspiron 16 5630
ChengMing 3910/3911
OptiPlex All-in-One 7410
Vostro 3020 Small Desktop
Vostro 3020 Tower Desktop
Inspiron 16 5620
Inspiron 14 5420
XPS 13 9315
Vostro 5620
XPS 13 9305
XPS 13 9300
Vostro 3910
Vostro 3710
ChengMing 3900
Inspiron 3910
XPS 13 7390
Dell G15 5510
Inspiron 7501
Inspiron 7500
Vostro 7500
Latitude 3410
Latitude 3510
Precision 5750
Inspiron 5509
Inspiron 7706 2-in-1
Inspiron 5502
Inspiron 7506 2-in-1
Inspiron 5409
Inspiron 5406 2-in-1
Precision 5550
Vostro 5502
Inspiron 5402
Vostro 5402
Latitude 3301
XPS 15 9500
XPS 17 9700
Inspiron 7306 2-in-1
Dell G15 5511
Inspiron 15 3511
Vostro 3400
Vostro 3500
Vostro 15 3510
XPS 13 7390 2-in-1
Inspiron 3501
Vostro 3401
Vostro 3501
Latitude 3400
Latitude 3500
Inspiron 5301
Vostro 5301
Inspiron 7400
Inspiron 7300
Latitude Rugged 7220EX
Latitude 7220 Rugged Extreme
Precision 3660
XPS 8940
XPS 13 9310 2-in-1
Precision 3460 XE Small Form Factor / Precision 3460 Small Form Factor
Precision 3260 XE Compact / Precision 3260 Compact
XPS 13 9310
RSA Authentication Manager
openssl-1_1-livepatches-debuginfo
openssl-1_1-livepatches
openssl-1_1-livepatches-debugsource
libopenssl1_1-debuginfo
openssl-1_1-debugsource
openssl-1_1-debuginfo
libopenssl1_1-hmac-32bit
libopenssl1_1-debuginfo-32bit
libopenssl1_1-hmac
libopenssl-1_1-devel
libopenssl-1_1-devel-32bit
openssl-1_1
libopenssl1_1
libopenssl1_1-32bit
openssl-1_1-doc
libopenssl1_1-32bit-debuginfo
openssl-help
openssl-devel
openssl-debugsource
openssl-debuginfo
openssl-libs
openssl
openssl-perl
libopenssl1_1-hmac-64bit
libopenssl1_1-64bit-debuginfo
libopenssl1_1-64bit
libopenssl-1_1-devel-64bit
openssl-solibs
libssl1.1 (Ubuntu package)
libssl3 (Ubuntu package)
openssl-fips-provider (Red Hat package)
libopenssl3-64bit-debuginfo
openssl-3-debugsource
libopenssl-3-devel
openssl-3-debuginfo
libopenssl3-debuginfo
libopenssl3
openssl-3
libopenssl3-32bit-debuginfo
libopenssl-3-devel-32bit
libopenssl3-32bit
openssl-3-doc
libopenssl3-64bit
libopenssl-3-devel-64bit
libssl3t64 (Ubuntu package)
libopenssl-3-fips-provider-32bit-debuginfo
libopenssl-3-fips-provider-debuginfo
libopenssl-3-fips-provider
libopenssl-3-fips-provider-32bit
libopenssl-3-fips-provider-64bit
libopenssl-3-fips-provider-64bit-debuginfo
openssl3
openssl (Red Hat package)
edk2 (Ubuntu package)
edk2-ovmf
edk2
edk2-debuginfo
python3-edk2-devel
edk2-help
edk2-aarch64
edk2-devel
edk2-debugsource
OpenShift API for Data Protection (OADP)
Multicluster Engine for Kubernetes
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM MaaS360 VPN Module
Dell EMC VxRail Appliance
IBM CICS TX Advanced

How to mitigate CVE-2024-4741

Install update from vendor's website.

OpenSSL - addressed in versions 1.1.1y, 3.0.14, 3.1.6, 3.2.2, 3.3.1
Oracle Solaris - update to 11.4 SRU 71
IBM Concert Software - update to 1.0.5
Voice Gateway - update to 1.0.8.12
Rapid Infrastructure Automation - update to 1.1.5.3
Guardium Data Security Center (GDSC) - update to 3.6.1
EasyApache - update to 4 2024-7-10
SecurityCenter - update to SC-202412.1
IBM Storage Scale System - addressed in versions 6.2.3.3, 7.0.0.0
LANTIME Operating System Firmware (LTOS) - update to 7.08.012
RSA Authentication Manager - update to 8.7 SP2 Patch 4
IBM Rational ClearQuest - addressed in versions 9.1.0.8, 10.0.7
Serv-U FTP Server - update to 15.5
PowerProtect Cyber Recovery - update to 19.18.0.2
Junos OS - addressed in versions 21.4R3-S8, 21.4R3-S9, 22.2R3-S5, 22.3R3-S4, 22.4R3-S3, 23.2R2-S2, 23.4R2-S1, 24.2R1-S1, 24.2R2, 24.4R1
HP-UX OpenSSL - update to A.03.00.15.001
openssl-1_1-livepatches-debuginfo - addressed in versions 0.4-150400.3.11.1, 0.4-150500.6.8.1, 0.5-150600.11.3.1, 0.5-150700.13.3.1
openssl-1_1-livepatches - addressed in versions 0.4-150400.3.11.1, 0.4-150500.6.8.1, 0.5-150600.11.3.1, 0.5-150700.13.3.1
openssl-1_1-livepatches-debugsource - addressed in versions 0.4-150400.3.11.1, 0.4-150500.6.8.1, 0.5-150600.11.3.1, 0.5-150700.13.3.1
Service Interconnect - addressed in versions 1, 1.4
libopenssl1_1-debuginfo - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
openssl-1_1-debugsource - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
openssl-1_1-debuginfo - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.107.1
libopenssl1_1-hmac - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1
libopenssl-1_1-devel - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
openssl-1_1 - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
libopenssl1_1 - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
libopenssl1_1-32bit - addressed in versions 1.1.1d-2.107.1, 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.1d-150200.11.91.1, 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
openssl-help - addressed in versions 1.1.1f-34, 1.1.1m-36, 1.1.1wa-7, 3.0.12-6
openssl-devel - addressed in versions 1.1.1f-34, 1.1.1m-36, 1.1.1wa-7, 3.0.12-6
openssl-debugsource - addressed in versions 1.1.1f-34, 1.1.1m-36, 1.1.1wa-7, 3.0.12-6
openssl-debuginfo - addressed in versions 1.1.1f-34, 1.1.1m-36, 1.1.1wa-7, 3.0.12-6
openssl-libs - addressed in versions 1.1.1f-34, 1.1.1m-36, 1.1.1wa-7, 3.0.12-6
openssl - addressed in versions 1.1.1f-34, 1.1.1m-36, 1.1.1wa-7, 3.0.12-6
openssl-perl - update to 1.1.1k-16.0.1
openssl - update to 1.1.1k-16.0.1
openssl-devel - update to 1.1.1k-16.0.1
openssl-libs - update to 1.1.1k-16.0.1
libopenssl1_1-hmac-64bit - addressed in versions 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1
libopenssl1_1-64bit-debuginfo - addressed in versions 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
libopenssl1_1-64bit - addressed in versions 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
libopenssl-1_1-devel-64bit - addressed in versions 1.1.1l-150400.7.69.1, 1.1.1l-150500.17.31.1, 1.1.1w-150600.5.3.1
openssl-perl - addressed in versions 1.1.1m-36, 1.1.1wa-7, 3.0.12-6
openssl-solibs - update to 1.1.1za
openssl - update to 1.1.1za
libssl1.1 (Ubuntu package) - update to 1.1.1f-1ubuntu2.23
Data Lakehouse - update to 1.3.0.0
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
Inspiron 24 5430 All-in-One - update to 1.9.0
Inspiron 27 7730 All-in-One - update to 1.9.0
Inspiron 16 7640 2-in-1 - update to 1.9.0
Alienware m16 R2 - update to 1.9.0
Latitude 3450 - update to 1.10.0
Latitude 3550 - update to 1.10.0
Precision 3280 CFF - update to 1.10.0
Inspiron 14 7440 2-in-1 - update to 1.10.0
Inspiron 14 5440 - update to 1.10.0
Vostro 14 3440 - update to 1.10.0
Precision 3680 Tower - update to 1.11.1
Inspiron 3030S - update to 1.12.0
Inspiron 3030 - update to 1.12.0
Vostro 3030S - update to 1.12.0
Vostro 3030 - update to 1.12.0
Inspiron 14 Plus 7440 - update to 1.12.0
Inspiron 16 Plus 7640 - update to 1.12.0
OptiPlex AIO 7420 - update to 1.12.1
OptiPlex 5055 A-Serial - update to 1.14.0
OptiPlex 5055 Ryzen APU - update to 1.14.0
OptiPlex 5055 Ryzen CPU - update to 1.14.0
Inspiron 27 7720 All-in-One - update to 1.16.1
Inspiron 24 5420 All-in-One - update to 1.16.1
Latitude 5495 - update to 1.17.0
Inspiron 14 5430 - update to 1.19.0
Inspiron 14 7430 2-in-1 - update to 1.19.0
Inspiron 16 7630 2-in-1 - update to 1.19.0
Vostro 16 5630 - update to 1.19.0
Inspiron 16 5630 - update to 1.19.0
ChengMing 3910/3911 - update to 1.22.0
OptiPlex All-in-One 7410 - update to 1.22.0
Vostro 3020 Small Desktop - update to 1.22.0
Vostro 3020 Tower Desktop - update to 1.22.0
Inspiron 16 5620 - update to 1.26.0
Inspiron 14 5420 - update to 1.26.0
XPS 13 9315 - update to 1.26.0
Vostro 5620 - update to 1.26.0
XPS 13 9305 - update to 1.26.1
XPS 13 9300 - update to 1.27.1
Vostro 3910 - update to 1.28.0
Vostro 3710 - update to 1.28.0
ChengMing 3900 - update to 1.28.0
Inspiron 3910 - update to 1.28.0
XPS 13 7390 - update to 1.28.1
Dell G15 5510 - update to 1.30.0
Inspiron 7501 - update to 1.31.1
Inspiron 7500 - update to 1.31.1
Vostro 7500 - update to 1.31.1
Latitude 3410 - update to 1.32.1
Latitude 3510 - update to 1.32.1
Precision 5750 - update to 1.33.1
Inspiron 5509 - update to 1.33.1
Inspiron 7706 2-in-1 - update to 1.33.1
Inspiron 5502 - update to 1.33.1
Inspiron 7506 2-in-1 - update to 1.33.1
Inspiron 5409 - update to 1.33.1
Inspiron 5406 2-in-1 - update to 1.33.1
Precision 5550 - update to 1.33.1
Vostro 5502 - update to 1.33.1
Inspiron 5402 - update to 1.33.1
Vostro 5402 - update to 1.33.1
Latitude 3301 - update to 1.33.1
XPS 15 9500 - update to 1.33.1
XPS 17 9700 - update to 1.33.1
Inspiron 7306 2-in-1 - update to 1.33.1
Dell G15 5511 - update to 1.34.0
Inspiron 15 3511 - update to 1.34.0
Vostro 3400 - update to 1.34.0
Vostro 3500 - update to 1.34.0
Vostro 15 3510 - update to 1.34.0
XPS 13 7390 2-in-1 - update to 1.34.1
Inspiron 3501 - update to 1.35.0
Vostro 3401 - update to 1.35.0
Vostro 3501 - update to 1.35.0
Latitude 3400 - update to 1.35.1
Latitude 3500 - update to 1.35.1
Inspiron 5301 - update to 1.36.1
Vostro 5301 - update to 1.36.1
Inspiron 7400 - update to 1.36.1
Inspiron 7300 - update to 1.36.1
Latitude Rugged 7220EX - update to 1.42.0
Latitude 7220 Rugged Extreme - update to 1.42.0
Multicluster Engine for Kubernetes - addressed in versions 2.5.8, 2.6.4, 2.7.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.10.7, 2.11.4, 2.11.7, 2.12.1, 2.12.3
Precision 3660 - update to 2.22.0
XPS 8940 - update to 2.25.0
XPS 13 9310 2-in-1 - update to 2.29.1
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.17
openssl-fips-provider (Red Hat package) - update to 3.0.7-6.el9_5
libopenssl3-64bit-debuginfo - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
libopenssl3 - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
openssl-3 - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
libopenssl3-64bit - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
libopenssl-3-devel-64bit - addressed in versions 3.0.8-150400.4.57.1, 3.0.8-150500.5.36.1, 3.1.4-150600.5.7.1
libssl3t64 (Ubuntu package) - update to 3.0.13-0ubuntu3.2
IBM MaaS360 VPN Module - update to 3.000.850
libopenssl-3-fips-provider-32bit-debuginfo - update to 3.1.4-150600.5.7.1
libopenssl-3-fips-provider-debuginfo - update to 3.1.4-150600.5.7.1
libopenssl-3-fips-provider - update to 3.1.4-150600.5.7.1
libopenssl-3-fips-provider-32bit - update to 3.1.4-150600.5.7.1
libopenssl-3-fips-provider-64bit - update to 3.1.4-150600.5.7.1
libopenssl-3-fips-provider-64bit-debuginfo - update to 3.1.4-150600.5.7.1
openssl3 - update to 3.2.2-2.1.el8
openssl (Red Hat package) - update to 3.2.2-6.el9_5
Precision 3460 XE Small Form Factor / Precision 3460 Small Form Factor - update to 3.12.0
Precision 3260 XE Compact / Precision 3260 Compact - update to 3.12.0
Red Hat OpenShift Dev Spaces - update to 3.17.0
XPS 13 9310 - update to 3.27.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.9
OpenShift Virtualization - update to 4.13.11
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.13, 4.15.9, 4.16.4, 4.17.1
IBM Spectrum Control - update to 5.4.12.1
OpenShift Logging - addressed in versions 5.8.16, 5.8.17, 5.8.19, 5.8.20, 5.9.10, 5.9.14
Dell Secure Connect Gateway - update to 5.26.00.18
Aruba Networking Fabric Composer - update to 7.3.0
IBM Rational Build Forge - update to 8.0.0.27
Dell EMC VxRail Appliance - update to 8.0.213
IBM Rational ClearCase - addressed in versions 9.1.0.8, 10.0.1.3, 11.0.0.3
IBM CICS TX Advanced - update to 10.1.0.0 ifix32
IBM QRadar WinCollect Agent - update to 10.1.11
Guardium Data Protection - update to 12.0p35
EMC Cloud Tiering Appliance - update to 13.2.0.2.31
CloudBoost Virtual Appliance - update to 19.12.0.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.20, 23.0.20
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2-ovmf - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2 - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-debuginfo - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
python3-edk2-devel - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-help - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-aarch64 - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-devel - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18
edk2-debugsource - addressed in versions 202002-27, 202011-23, 202011-24, 202308-17, 202308-18

External References

Related Security Bulletins