- What: Security update for edk2
- Impact: Addresses an out-of-bounds read/write vulnerability
Red Hat Product Errata RHSA-2026:65132 - Security Advisory Issued: 2026-09-08 Updated: 2026-09-08 RHSA-2026:65132 - Security Advisory Overview Updated Packages Synopsis Moderate: edk2 security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for edk2 is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. Security Fix(es): openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2396054 - CVE-2025-9230 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap CVEs CVE-2025-9230 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM edk2-20241117-2.el10_0.2.src.rpm SHA-256: 4fd5c24facbf0d6289286a6e9efaa6caa2251d7561908970f050aef57964ce02 x86_64 edk2-ovmf-20241117-2.el10_0.2.noarch.rpm SHA-256: db95da7552a540c9efd5229c0cd6149ca0cc4f72242512e94a513259ef0b8a26 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM edk2-20241117-2.el10_0.2.src.rpm SHA-256: 4fd5c24facbf0d6289286a6e9efaa6caa2251d7561908970f050aef57964ce02 aarch64 edk2-aarch64-20241117-2.el10_0.2.noarch.rpm SHA-256: c3c55f34984ad551094755e76fe7c37c7701921cfa3fd335548c4f54081be3b7 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 SRPM x86_64 edk2-aarch64-20241117-2.el10_0.2.noarch.rpm SHA-256: c3c55f34984ad551094755e76fe7c37c7701921cfa3fd335548c4f54081be3b7 edk2-debugsource-20241117-2.el10_0.2.x86_64.rpm SHA-256: 6e8b0d2d1e7b7a6611f193160f16255d01ce375ae2f897ba97fa7e5ecb2c48e7 edk2-tools-20241117-2.el10_0.2.x86_64.rpm SHA-256: b810664b9391d964e2bc61584b53ffc97e002fb54fc6344abb5a55213b2fe44a edk2-tools-debuginfo-20241117-2.el10_0.2.x86_64.rpm SHA-256: 6229abc2b8d35d4fe49b5bc1c41f428b20770ea3c9701264c459183d5fbb122d edk2-tools-doc-20241117-2.el10_0.2.noarch.rpm SHA-256: 6aeac66ff53f88d0137f988247c41eb51d9aea83f4573d62cb5ab065ecf05040 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0 SRPM ppc64le edk2-aarch64-20241117-2.el10_0.2.noarch.rpm SHA-256: c3c55f34984ad551094755e76fe7c37c7701921cfa3fd335548c4f54081be3b7 edk2-ovmf-20241117-2.el10_0.2.noarch.rpm SHA-256: db95da7552a540c9efd5229c0cd6149ca0cc4f72242512e94a513259ef0b8a26 Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0 SRPM s390x edk2-aarch64-20241117-2.el10_0.2.noarch.rpm SHA-256: c3c55f34984ad551094755e76fe7c37c7701921cfa3fd335548c4f54081be3b7 edk2-ovmf-20241117-2.el10_0.2.noarch.rpm SHA-256: db95da7552a540c9efd5229c0cd6149ca0cc4f72242512e94a513259ef0b8a26 Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0 SRPM aarch64 edk2-debugsource-20241117-2.el10_0.2.aarch64.rpm SHA-256: 62a977ddd905e67384196784a27b3c7acc072b7cb4c8d99739ed2219140af57c edk2-ovmf-20241117-2.el10_0.2.noarch.rpm SHA-256: db95da7552a540c9efd5229c0cd6149ca0cc4f72242512e94a513259ef0b8a26 edk2-tools-20241117-2.el10_0.2.aarch64.rpm SHA-256: ec117028049cd33ba2fcc10de5d28bbc5f35fc79d4ded3b29c0611aa62af0c0f edk2-tools-debuginfo-20241117-2.el10_0.2.aarch64.rpm SHA-256: a9973d96d00b71ab68efd55b4744bf00517d933dd39dcac18fef5b4e20182a1e edk2-tools-doc-20241117-2.el10_0.2.noarch.rpm SHA-256: 6aeac66ff53f88d0137f988247c41eb51d9aea83f4573d62cb5ab065ecf05040 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM edk2-20241117-2.el10_0.2.src.rpm SHA-256: 4fd5c24facbf0d6289286a6e9efaa6caa2251d7561908970f050aef57964ce02 aarch64 edk2-aarch64-20241117-2.el10_0.2.noarch.rpm SHA-256: c3c55f34984ad551094755e76fe7c37c7701921cfa3fd335548c4f54081be3b7 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 SRPM edk2-20241117-2.el10_0.2.src.rpm SHA-256: 4fd5c24facbf0d6289286a6e9efaa6caa2251d7561908970f050aef57964ce02 x86_64 edk2-ovmf-20241117-2.el10_0.2.noarch.rpm SHA-256: db95da7552a540c9efd5229c0cd6149ca0cc4f72242512e94a513259ef0b8a26 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .