{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"Low"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"edk2 security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for edk2 is now available for openEuler-24.03-LTS-SP3",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications.\n\nSecurity Fix(es):\n\nIssue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are affected by this\nissue.(CVE-2026-42770)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for edk2 is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of low. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"Low",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"edk2",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-2891",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2891"
			},
			{
				"summary":"CVE-2026-42770",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42770&packageName=edk2"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42770"
			},
			{
				"summary":"openEuler-SA-2026-2891 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2891.json"
			}
		],
		"title":"An update for edk2 is now available for openEuler-24.03-LTS-SP3",
		"tracking":{
			"initial_release_date":"2026-07-13T11:35:16+08:00",
			"revision_history":[
				{
					"date":"2026-07-13T11:35:16+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-07-13T11:35:16+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-07-13T11:35:16+08:00",
			"id":"openEuler-SA-2026-2891",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"openEuler-24.03-LTS-SP3",
									"name":"openEuler-24.03-LTS-SP3"
								},
								"name":"openEuler-24.03-LTS-SP3",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"edk2-debuginfo-202308-43.oe2403sp3.aarch64.rpm",
									"name":"edk2-debuginfo-202308-43.oe2403sp3.aarch64.rpm"
								},
								"name":"edk2-debuginfo-202308-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"edk2-debugsource-202308-43.oe2403sp3.aarch64.rpm",
									"name":"edk2-debugsource-202308-43.oe2403sp3.aarch64.rpm"
								},
								"name":"edk2-debugsource-202308-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"edk2-devel-202308-43.oe2403sp3.aarch64.rpm",
									"name":"edk2-devel-202308-43.oe2403sp3.aarch64.rpm"
								},
								"name":"edk2-devel-202308-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"edk2-debuginfo-202308-43.oe2403sp3.x86_64.rpm",
									"name":"edk2-debuginfo-202308-43.oe2403sp3.x86_64.rpm"
								},
								"name":"edk2-debuginfo-202308-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"edk2-debugsource-202308-43.oe2403sp3.x86_64.rpm",
									"name":"edk2-debugsource-202308-43.oe2403sp3.x86_64.rpm"
								},
								"name":"edk2-debugsource-202308-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"edk2-devel-202308-43.oe2403sp3.x86_64.rpm",
									"name":"edk2-devel-202308-43.oe2403sp3.x86_64.rpm"
								},
								"name":"edk2-devel-202308-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"edk2-aarch64-202308-43.oe2403sp3.noarch.rpm",
									"name":"edk2-aarch64-202308-43.oe2403sp3.noarch.rpm"
								},
								"name":"edk2-aarch64-202308-43.oe2403sp3.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"edk2-help-202308-43.oe2403sp3.noarch.rpm",
									"name":"edk2-help-202308-43.oe2403sp3.noarch.rpm"
								},
								"name":"edk2-help-202308-43.oe2403sp3.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"edk2-ovmf-202308-43.oe2403sp3.noarch.rpm",
									"name":"edk2-ovmf-202308-43.oe2403sp3.noarch.rpm"
								},
								"name":"edk2-ovmf-202308-43.oe2403sp3.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-edk2-devel-202308-43.oe2403sp3.noarch.rpm",
									"name":"python3-edk2-devel-202308-43.oe2403sp3.noarch.rpm"
								},
								"name":"python3-edk2-devel-202308-43.oe2403sp3.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"edk2-debuginfo-202308-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:edk2-debuginfo-202308-43.oe2403sp3.aarch64",
					"name":"edk2-debuginfo-202308-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"edk2-debugsource-202308-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:edk2-debugsource-202308-43.oe2403sp3.aarch64",
					"name":"edk2-debugsource-202308-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"edk2-devel-202308-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:edk2-devel-202308-43.oe2403sp3.aarch64",
					"name":"edk2-devel-202308-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"edk2-debuginfo-202308-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:edk2-debuginfo-202308-43.oe2403sp3.x86_64",
					"name":"edk2-debuginfo-202308-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"edk2-debugsource-202308-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:edk2-debugsource-202308-43.oe2403sp3.x86_64",
					"name":"edk2-debugsource-202308-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"edk2-devel-202308-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:edk2-devel-202308-43.oe2403sp3.x86_64",
					"name":"edk2-devel-202308-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"edk2-aarch64-202308-43.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:edk2-aarch64-202308-43.oe2403sp3.noarch",
					"name":"edk2-aarch64-202308-43.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"edk2-help-202308-43.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:edk2-help-202308-43.oe2403sp3.noarch",
					"name":"edk2-help-202308-43.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"edk2-ovmf-202308-43.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:edk2-ovmf-202308-43.oe2403sp3.noarch",
					"name":"edk2-ovmf-202308-43.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-edk2-devel-202308-43.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-edk2-devel-202308-43.oe2403sp3.noarch",
					"name":"python3-edk2-devel-202308-43.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2026-42770",
			"notes":[
				{
					"text":"Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are affected by this\nissue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:edk2-debuginfo-202308-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:edk2-debugsource-202308-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:edk2-devel-202308-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:edk2-debuginfo-202308-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:edk2-debugsource-202308-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:edk2-devel-202308-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:edk2-aarch64-202308-43.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:edk2-help-202308-43.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:edk2-ovmf-202308-43.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:python3-edk2-devel-202308-43.oe2403sp3.noarch"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:edk2-debuginfo-202308-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:edk2-debugsource-202308-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:edk2-devel-202308-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:edk2-debuginfo-202308-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:edk2-debugsource-202308-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:edk2-devel-202308-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:edk2-aarch64-202308-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:edk2-help-202308-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:edk2-ovmf-202308-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-edk2-devel-202308-43.oe2403sp3.noarch"
					],
					"details":"edk2 security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2891"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"LOW",
						"baseScore":3.7,
						"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:edk2-debuginfo-202308-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:edk2-debugsource-202308-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:edk2-devel-202308-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:edk2-debuginfo-202308-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:edk2-debugsource-202308-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:edk2-devel-202308-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:edk2-aarch64-202308-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:edk2-help-202308-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:edk2-ovmf-202308-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-edk2-devel-202308-43.oe2403sp3.noarch"
					]
				}
			],
			"threats":[
				{
					"details":"Low",
					"category":"impact"
				}
			],
			"title":"CVE-2026-42770"
		}
	]
}