CVE-2021-28211: Medium severity tianocore edk ii vulnerability
Published Jun 11, 2021
·Updated
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
Affected Software
2 affected componentsFixes available
Tianocore edk2=202008
debian/edk2
2020.11-2+deb11u22022.11-6+deb12u22022.11-6+deb12u12025.02-62025.02-7
Remediation
Patch Available
Event History
Jun 11, 2021
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionWeakness
Oct 10, 2024
Data Sourced
via Launchpad·06:12 AM
Description
Oct 14, 2024
Data Sourced
via Ubuntu·06:12 AM
RemedyDescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·02:46 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this heap overflow in LzmaUefiDecompressGetInfo function in EDK II?
The vulnerability ID is CVE-2021-28211.
2
What software is affected by this vulnerability?
The Tianocore EDK2 version 202008 is affected by this vulnerability.
3
How severe is this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 6.7.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-787 and CWE-122.
5
Is there a reference to more information about this vulnerability?
Yes, you can find more information about this vulnerability at the following link: https://bugzilla.tianocore.org/show_bug.cgi?id=1816