CVE-2019-14559: High severity Tianocore edk2 vulnerability
Last updated 25 August 2025
Other sources
Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-14559?
CVE-2019-14559 is a vulnerability in the EDK II firmware that allows an unauthenticated user to potentially enable denial of service via network access.
Which software is affected by CVE-2019-14559?
The EDK II package in Debian and Ubuntu versions 0~20181115.85588389-3+deb10u3, 2020.11-2+deb11u1, 2022.11-6, 2023.05-2, and versions 0~20180205., 0~20190606.20, and 0~20160408. of the package in Ubuntu are affected by CVE-2019-14559.
What is the severity of CVE-2019-14559?
CVE-2019-14559 has a severity rating of 7.5 (High).
How can I fix CVE-2019-14559?
To fix CVE-2019-14559, apply the recommended patches for the affected EDK II package versions 0~20181115.85588389-3+deb10u3, 2020.11-2+deb11u1, 2022.11-6, and 2023.05-2 on Debian, and versions 0~20180205., 0~20190606.20, and 0~20160408. on Ubuntu.
Where can I find more information about CVE-2019-14559?
More information about CVE-2019-14559 can be found on the following references: [Bugzilla](https://bugzilla.tianocore.org/show_bug.cgi?id=2031), [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2021/04/msg00032.html), and [Launchpad Bugs](https://launchpad.net/bugs/cve/CVE-2019-14559).