Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.6
Red Hat's edk2 Software May Allow Unauthorized Code Execution
RHSA-2026:3164
Summary
A security issue was found in the edk2 software, which is used in Red Hat products. This issue could allow an attacker to execute unauthorized code, potentially leading to data theft or system compromise. Users are advised to apply the latest update to fix this issue.
What to do
- Update redhat edk2 to version 0:20231122-6.el9_4.10.
- Update redhat edk2-aarch64 to version 0:20231122-6.el9_4.10.
- Update redhat edk2-debugsource to version 0:20231122-6.el9_4.10.
- Update redhat edk2-ovmf to version 0:20231122-6.el9_4.10.
- Update redhat edk2-tools to version 0:20231122-6.el9_4.10.
- Update redhat edk2-tools-debuginfo to version 0:20231122-6.el9_4.10.
- Update redhat edk2-tools-doc to version 0:20231122-6.el9_4.10.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| redhat | edk2 | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-aarch64 | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-debugsource | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-ovmf | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-tools | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-tools-debuginfo | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-tools-doc | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2 | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-aarch64 | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-debugsource | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-ovmf | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-tools | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-tools-debuginfo | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
| redhat | edk2-tools-doc | <= 0:20231122-6.el9_4.10 | 0:20231122-6.el9_4.10 |
Original title
Red Hat Security Advisory: edk2 security update
osv CVSS3.1
5.6
- https://access.redhat.com/errata/RHSA-2026:3164 Vendor Advisory
- https://access.redhat.com/security/updates/classification/#moderate Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2396054 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3164.j... Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2025-9230 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-9230 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-9230 Vendor Advisory
Published: 25 Feb 2026 · Updated: 6 Mar 2026 · First seen: 6 Mar 2026