CVE-2018-12180: Buffer Overflow
A flaw was found in edk2. When registering a Ram disk whose size is not a multiple of 512 bytes, the BlockIo protocol produced by the RamDiskDxe driver will incur memory read/write overrun. The memory overrun will happen when reading/writing the last block on the Ram disk.
Upstream Bug: https://bugzilla.tianocore.org/showbug.cgi?id=1134
Upstream Patch: https://lists.01.org/pipermail/edk2-devel/2019-February/037248.html https://lists.01.org/pipermail/edk2-devel/2019-February/037249.html https://lists.01.org/pipermail/edk2-devel/2019-February/037250.html
Other sources
Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-12180?
CVE-2018-12180 is a vulnerability in the BlockIo service for EDK II that may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure, and/or denial of service via network access.
How severe is CVE-2018-12180?
CVE-2018-12180 has a severity score of 8.8 out of 10, indicating a high severity vulnerability.
How can an unauthenticated user exploit CVE-2018-12180?
An unauthenticated user can potentially exploit CVE-2018-12180 through network access, leading to potential privilege escalation, information disclosure, and denial of service.
Which software is affected by CVE-2018-12180?
The EDK II package versions 0~20181115.85588389-3+deb10u3, 2020.11-2+deb11u1, 2022.11-6, and 2023.05-2 in Debian, and version 0~20180205. in Ubuntu Bionic, Ubuntu upstream, and Ubuntu Xenial are affected by CVE-2018-12180.
Where can I find more information about CVE-2018-12180?
You can find more information about CVE-2018-12180 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00046.html](http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00046.html), [https://access.redhat.com/errata/RHSA-2019:0809](https://access.redhat.com/errata/RHSA-2019:0809), [https://access.redhat.com/errata/RHSA-2019:0968](https://access.redhat.com/errata/RHSA-2019:0968).