summaryrefslogtreecommitdiff
path: root/BaseTools/Source/Python/Workspace
diff options
context:
space:
mode:
authorMikey Strauss <mdstrauss91@gmail.com>2026-07-31 16:29:59 +0300
committermergify[bot] <37929162+mergify[bot]@users.noreply.github.com>2026-08-03 04:40:40 +0300
commit4bd628ce9844c04623ade7b875efaa19a6b57b35 (patch)
tree61f3347c81f4f3c3a511e60eb320d7d0e50931b4 /BaseTools/Source/Python/Workspace
parentd45f882a1bf077f7e8e828fc9dfb14f3187142c1 (diff)
downloadedk2-4bd628ce9844c04623ade7b875efaa19a6b57b35.tar.xz
SecurityPkg/DeviceSecurity: Update libspdm submodule to 3.8.2
The libspdm submodule was pinned at 3.7.0 (2025-04-03), three releases behind upstream 3.8.2 (2026-04-03). libspdm processes untrusted responder (device) data in the SPDM device attestation path, so tracking upstream keeps that parsing current with fixes and hardening. Two responder-side advisories were resolved between 3.7.0 and 3.8.2: - GHSA-j54w-759w-xj3m: out-of-bounds write in GET_CSR handling. - GHSA-m4wc-xmvg-369f: integer overflow / out-of-bounds read in GET_MEASUREMENT_EXTENSION_LOG handling. Both are responder-side. edk2 links SpdmRequesterLib (it acts as the SPDM Requester that verifies an untrusted device Responder), so these responder handlers are not built into edk2 images; this update is defense-in-depth rather than a fix for a path reachable in edk2 today. The libspdm sources referenced by the SpdmLib INFs are unchanged in 3.8.2 (the only additions are the optional ENDPOINT_INFO capability sources, which edk2 does not enable), so no INF change is required. Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Chris Fernald <chfernal@microsoft.com> Signed-off-by: Mikey Strauss <mdstrauss91@gmail.com>
Diffstat (limited to 'BaseTools/Source/Python/Workspace')
0 files changed, 0 insertions, 0 deletions