SUSE-SU-2023:1940-1

Advisory lineage Upstream: 2 Downstream: 0
Published: 21 Apr 2023, 10:00
Last modified:04 Feb 2026, 04:10

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Apr 2023, 10:00
Published
Vulnerability first disclosed
04 Feb 2026, 04:10
Last Modified
Vulnerability information updated

Description

Security update for ovmf This update for ovmf fixes the following issues: - CVE-2019-14560: Fixed potential secure boot bypass via an improper check of GetEfiGlobalVariable2 (bsc#1174246). - CVE-2021-38578: Fixed underflow in MdeModulePkg/PiSmmCore SmmEntryPointAdd (bsc#1196741).

Affected Systems

  • suseovmf&distro=SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS

    < 2017+git1510945757.b2662641d5-150000.5.46.1

  • suseovmf&distro=SUSE Linux Enterprise Server 15 SP1-LTSS

    < 2017+git1510945757.b2662641d5-150000.5.46.1

  • suseovmf&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP1

    < 2017+git1510945757.b2662641d5-150000.5.46.1

References (5)