CVE-2021-28210: High severity tianocore edk ii vulnerability
Published Jun 11, 2021
·Updated
An unlimited recursion in DxeCore in EDK II.
Affected Software
2 affected componentsFixes available
Tianocore edk2<202008
debian/edk2
2020.11-2+deb11u22022.11-6+deb12u22022.11-6+deb12u12025.02-62025.02-7
Remediation
Patch Available
Event History
Jun 11, 2021
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionWeakness
Oct 10, 2024
Data Sourced
via Launchpad·06:12 AM
Description
Oct 14, 2024
Data Sourced
via Ubuntu·06:12 AM
RemedyDescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·03:47 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-28210.
2
What is the severity of CVE-2021-28210?
The severity of CVE-2021-28210 is high with a score of 7.8.
3
What is the affected software for CVE-2021-28210?
The affected software for CVE-2021-28210 is Tianocore EDK2 version up to exclusive 202008.
4
What is the description of CVE-2021-28210?
CVE-2021-28210 is an unlimited recursion vulnerability in DxeCore in EDK II.
5
How can I fix CVE-2021-28210?
To fix CVE-2021-28210, it is recommended to update to a version of Tianocore EDK2 that is not affected by this vulnerability.