edk2 (2025.02-9)
[PTS] [DDPO]
OK: VCS matches the version in the archive
- Git: https://salsa.debian.org/qemu-team/edk2.git
-
- Branch: debian/latest
- Path: debian/changelog
- Repo size: 23289856
- Browser: https://salsa.debian.org/qemu-team/edk2
- Last scan: 2025-09-02 03:02:41+00
- Next scan: 2025-09-10 10:31:00+00
- Merge requests: 6
- Debian changelog in Git:
edk2 (2025.02-9) unstable; urgency=medium
* Cherry-pick openssl fix for timing side-channel in ECDSA signature
computation, CVE-2024-13176.
- d/p/0001-Fix-timing-side-channel-in-ECDSA-signature-computati.patch
* Fix out-of-bounds memory access in NetworkPkg/IScsiDxe, CVE-2024-38805.
(Closes: #1111100).
- d/p/0001-NetworkPkg-IScsiDxe-Fix-for-out-of-bound-memory-acce.patch
* Use virt-firmware to enroll default keys.
* Initialize the Secure Boot dbx in *.ms.fd with the latest revocations.
The dbx previously only contained the hash of an empty file.
* Safe handling of IDT register on SMM entry, CVE-2025-3770.
(Closes: #1110533).
- d/p/0001-UefiCpuPkg-PiSmmCpuDxeSmm-Safe-handling-of-IDT-regis.patch
* Add amdsev image. Thanks to Lukas Märdian. (Closes: #1103961).
-- dann frazier <dannf@debian.org> Mon, 01 Sep 2025 14:16:19 -0600
- This branch is even with tag debian/2025.02-9