CVE-2018-12180: Buffer Overflow

Published Feb 26, 2019
·
Updated

A flaw was found in edk2. When registering a Ram disk whose size is not a multiple of 512 bytes, the BlockIo protocol produced by the RamDiskDxe driver will incur memory read/write overrun. The memory overrun will happen when reading/writing the last block on the Ram disk.

Upstream Bug: https://bugzilla.tianocore.org/showbug.cgi?id=1134

Upstream Patch: https://lists.01.org/pipermail/edk2-devel/2019-February/037248.html https://lists.01.org/pipermail/edk2-devel/2019-February/037249.html https://lists.01.org/pipermail/edk2-devel/2019-February/037250.html

Other sources

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

Launchpad

Affected Software

3 affected componentsFixes available
Tianocore EDK II
openSUSE Leap=15.0
debian/edk2
2020.11-2+deb11u22020.11-2+deb11u32022.11-6+deb12u22022.11-6+deb12u12025.02-8+deb13u12025.02-92025.11-4

Event History

Feb 26, 2019
Data Sourced
via Red Hat·05:40 PM
DescriptionSeverityAffected Software
Mar 27, 2019
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
DescriptionWeakness
Data Sourced
via NVD·08:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·04:24 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:25 PM
DescriptionAffected Software
Data Sourced
via Launchpad·04:25 PM
Description

Frequently Asked Questions

1

What is CVE-2018-12180?

CVE-2018-12180 is a vulnerability in the BlockIo service for EDK II that may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure, and/or denial of service via network access.

2

How severe is CVE-2018-12180?

CVE-2018-12180 has a severity score of 8.8 out of 10, indicating a high severity vulnerability.

3

How can an unauthenticated user exploit CVE-2018-12180?

An unauthenticated user can potentially exploit CVE-2018-12180 through network access, leading to potential privilege escalation, information disclosure, and denial of service.

4

Which software is affected by CVE-2018-12180?

The EDK II package versions 0~20181115.85588389-3+deb10u3, 2020.11-2+deb11u1, 2022.11-6, and 2023.05-2 in Debian, and version 0~20180205. in Ubuntu Bionic, Ubuntu upstream, and Ubuntu Xenial are affected by CVE-2018-12180.

5

Where can I find more information about CVE-2018-12180?

You can find more information about CVE-2018-12180 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00046.html](http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00046.html), [https://access.redhat.com/errata/RHSA-2019:0809](https://access.redhat.com/errata/RHSA-2019:0809), [https://access.redhat.com/errata/RHSA-2019:0968](https://access.redhat.com/errata/RHSA-2019:0968).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203