SUSE-SU-2023:1921-1

Advisory lineage Upstream: 2 Downstream: 0
Published: 19 Apr 2023, 16:07
Last modified:04 Feb 2026, 04:39

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Apr 2023, 16:07
Published
Vulnerability first disclosed
04 Feb 2026, 04:39
Last Modified
Vulnerability information updated

Description

Security update for ovmf This update for ovmf fixes the following issues: - CVE-2019-14560: Fixed potential secure boot bypass via an improper check of GetEfiGlobalVariable2 (bsc#1174246). - CVE-2021-38578: Fixed underflow in MdeModulePkg/PiSmmCore SmmEntryPointAdd (bsc#1196741).

Affected Systems

  • suseovmf&distro=SUSE Enterprise Storage 7

    < 201911-150200.7.27.1

  • suseovmf&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 201911-150200.7.27.1

  • suseovmf&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 201911-150200.7.27.1

  • suseovmf&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 201911-150200.7.27.1

References (5)