EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Edk2 | Tianocore | * | 202311 (including) |
Red Hat Enterprise Linux 8 | RedHat | edk2-0:20220126gitbb1bba3d77-13.el8_10 | * |
Red Hat Enterprise Linux 9 | RedHat | edk2-0:20231122-6.el9_4.2 | * |
Edk2 | Ubuntu | bionic | * |
Edk2 | Ubuntu | focal | * |
Edk2 | Ubuntu | jammy | * |
Edk2 | Ubuntu | lunar | * |
Edk2 | Ubuntu | mantic | * |
Edk2 | Ubuntu | trusty | * |
Edk2 | Ubuntu | xenial | * |