From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by spool.mail.gandi.net (Postfix) with ESMTPS id 1763F7803D0 for ; Wed, 17 Jan 2024 22:47:36 +0000 (UTC) DKIM-Signature: a=rsa-sha256; bh=i5vQ2VTXUslynApaph9waSmLiEjkCcqo8vfXk8xq99U=; c=relaxed/simple; d=groups.io; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References:MIME-Version:Precedence:List-Subscribe:List-Help:Sender:List-Id:Mailing-List:Delivered-To:Reply-To:List-Unsubscribe-Post:List-Unsubscribe:Content-Transfer-Encoding; s=20140610; t=1705531655; v=1; b=Dx/AROdlvTAesVFHRI7mA/UBasI4kcdToL0p6V+z4tC9kq8/CgW46fDvBQhgP8Z1WaJuckON nH/rx8oc5f0UmWC/2Z2RiSSRKVsAWZEJiti+Qk5wXXHsCfT/FlyxWarEN7tMLNBW0SwoU0xetG/ ciuAYVC0K/c26aGklozIsNPk= X-Received: by 127.0.0.2 with SMTP id v0IWYY7687511xJAtQ72foq0; Wed, 17 Jan 2024 14:47:35 -0800 X-Received: from mail-ot1-f41.google.com (mail-ot1-f41.google.com [209.85.210.41]) by mx.groups.io with SMTP id smtpd.web10.1547.1705531654512698932 for ; Wed, 17 Jan 2024 14:47:34 -0800 X-Received: by mail-ot1-f41.google.com with SMTP id 46e09a7af769-6dde528dbe8so5451250a34.0 for ; Wed, 17 Jan 2024 14:47:34 -0800 (PST) X-Gm-Message-State: wBRUhQAu2oMEhlVP0bTpKP8Sx7686176AA= X-Google-Smtp-Source: AGHT+IGonmVOI/1fDrn4smyZMqY9+IcBnoc2zcOoBjSQ7YYB4Vzyq9H0Pv0QQzZ8OaTcOB/MvBqJdQ== X-Received: by 2002:a05:6870:d14c:b0:210:a2dc:772a with SMTP id f12-20020a056870d14c00b00210a2dc772amr1734702oac.87.1705531653749; Wed, 17 Jan 2024 14:47:33 -0800 (PST) X-Received: from localhost.localdomain ([131.107.1.227]) by smtp.gmail.com with ESMTPSA id h10-20020a65518a000000b0059d6f5196fasm139973pgq.78.2024.01.17.14.47.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 17 Jan 2024 14:47:33 -0800 (PST) From: "Doug Flick via groups.io" To: devel@edk2.groups.io Cc: "Douglas Flick [MSFT]" , Jiewen Yao , Rahul Kumar Subject: [edk2-devel] [PATCH 3/3] SecurityPkg: : Updating SecurityFixes.yaml after symbol rename Date: Wed, 17 Jan 2024 14:47:22 -0800 Message-ID: <5e0e851e97459e183420178888d4fcdadc2f1ae1.1705529990.git.doug.edk2@gmail.com> In-Reply-To: References: MIME-Version: 1.0 Precedence: Bulk List-Subscribe: List-Help: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,dougflick@microsoft.com List-Unsubscribe-Post: List-Unsubscribe=One-Click List-Unsubscribe: Content-Transfer-Encoding: quoted-printable X-GND-Status: LEGIT Authentication-Results: spool.mail.gandi.net; dkim=pass header.d=groups.io header.s=20140610 header.b="Dx/AROdl"; dmarc=none; spf=pass (spool.mail.gandi.net: domain of bounce@groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce@groups.io Adding the new commit titles for the symbol renames Cc: Jiewen Yao Cc: Rahul Kumar Signed-off-by: Doug Flick [MSFT] --- SecurityPkg/SecurityFixes.yaml | 28 +++++++++++++++++----------- 1 file changed, 17 insertions(+), 11 deletions(-) diff --git a/SecurityPkg/SecurityFixes.yaml b/SecurityPkg/SecurityFixes.yaml index 833fb827a96c..b4006b42b89e 100644 --- a/SecurityPkg/SecurityFixes.yaml +++ b/SecurityPkg/SecurityFixes.yaml @@ -9,28 +9,34 @@ CVE_2022_36763: - "SecurityPkg: DxeTpm2Measurement: SECURITY PATCH 4117 - CVE 2022-367= 63"=0D - "SecurityPkg: DxeTpmMeasurement: SECURITY PATCH 4117 - CVE 2022-3676= 3"=0D - "SecurityPkg: : Adding CVE 2022-36763 to SecurityFixes.yaml"=0D + - "SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4117/4118 symbol= rename"=0D + - "SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4117/4118 symbol = rename"=0D + - "SecurityPkg: : Updating SecurityFixes.yaml after symbol rename"=0D cve: CVE-2022-36763=0D date_reported: 2022-10-25 11:31 UTC=0D description: (CVE-2022-36763) - Heap Buffer Overflow in Tcg2MeasureGptTa= ble()=0D note: This patch is related to and supersedes TCBZ2168=0D files_impacted:=0D - - Library\DxeTpm2MeasureBootLib\DxeTpm2MeasureBootLib.c=0D - - Library\DxeTpmMeasureBootLib\DxeTpmMeasureBootLib.c=0D + - Library\DxeTpm2MeasureBootLib\DxeTpm2MeasureBootLib.c=0D + - Library\DxeTpmMeasureBootLib\DxeTpmMeasureBootLib.c=0D links:=0D - - https://bugzilla.tianocore.org/show_bug.cgi?id=3D4117=0D - - https://bugzilla.tianocore.org/show_bug.cgi?id=3D2168=0D - - https://bugzilla.tianocore.org/show_bug.cgi?id=3D1990=0D + - https://bugzilla.tianocore.org/show_bug.cgi?id=3D4117=0D + - https://bugzilla.tianocore.org/show_bug.cgi?id=3D2168=0D + - https://bugzilla.tianocore.org/show_bug.cgi?id=3D1990=0D CVE_2022_36764:=0D commit_titles:=0D - - "SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4118 - CVE 2022= -36764"=0D - - "SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4118 - CVE 2022-= 36764"=0D - - "SecurityPkg: : Adding CVE 2022-36764 to SecurityFixes.yaml"=0D + - "SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4118 - CVE 2022-= 36764"=0D + - "SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4118 - CVE 2022-3= 6764"=0D + - "SecurityPkg: : Adding CVE 2022-36764 to SecurityFixes.yaml"=0D + - "SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4117/4118 symbol= rename"=0D + - "SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4117/4118 symbol = rename"=0D + - "SecurityPkg: : Updating SecurityFixes.yaml after symbol rename"=0D cve: CVE-2022-36764=0D date_reported: 2022-10-25 12:23 UTC=0D description: Heap Buffer Overflow in Tcg2MeasurePeImage()=0D note:=0D files_impacted:=0D - - Library\DxeTpm2MeasureBootLib\DxeTpm2MeasureBootLib.c=0D - - Library\DxeTpmMeasureBootLib\DxeTpmMeasureBootLib.c=0D + - Library\DxeTpm2MeasureBootLib\DxeTpm2MeasureBootLib.c=0D + - Library\DxeTpmMeasureBootLib\DxeTpmMeasureBootLib.c=0D links:=0D - - https://bugzilla.tianocore.org/show_bug.cgi?id=3D4118=0D + - https://bugzilla.tianocore.org/show_bug.cgi?id=3D4118=0D --=20 2.43.0 -=-=-=-=-=-=-=-=-=-=-=- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#113969): https://edk2.groups.io/g/devel/message/113969 Mute This Topic: https://groups.io/mt/103797466/7686176 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [rebecca@openfw.io] -=-=-=-=-=-=-=-=-=-=-=-