Usn
Reporting by Ubuntu Security NoticesRead the original at ubuntu.com
Executive Summary
Facts Only
* EDK II incorrectly handled CMS key unwrapping in the embedded OpenSSL library, potentially causing a heap buffer overflow and denial of service. This affected Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS (CVE-2026-63072).
* EDK II incorrectly handled CMP protection verification in the embedded OpenSSL library, potentially causing a denial of service. This affected Ubuntu 24.04 LTS and 26.04 LTS (CVE-2026-63076).
* EDK II incorrectly buffered DTLS records in the embedded OpenSSL library, potentially causing excessive memory consumption and denial of service to a remote attacker (CVE-2026-54874).
* Incorrect verification of AEAD tags in the embedded OpenSSL library allowed an attacker to cause EDK II to accept forged messages. This affected Ubuntu 24.04 LTS and 26.04 LTS (CVE-2026-75803).
* Updates require specific package versions for various Ubuntu releases, such as `ovmf` and `qemu-efi-aarch64`, depending on the target operating system version.
Full Take
From the original · Ubuntu Security Notices
Packages - edk2 - UEFI firmware for virtual machines Details It was discovered that EDK II incorrectly handled CMS key unwrapping in the embedded OpenSSL library. An attacker could possibly use this issue to cause a heap buffer overflow, resulting in a denial of service.Read the full story at ubuntu.com
Sentinel — Human
This text reads like a direct translation or compilation of official security advisories and package management instructions, indicating a high probability of human-mediated factual reporting rather than purely synthetic generation.
