First published: Fri Jun 11 2021(Updated: )
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
Credit: infosec@edk2.groups.io infosec@edk2.groups.io
Affected Software | Affected Version | How to fix |
---|---|---|
Tianocore EDK2 | =202008 | |
debian/edk2 | 2020.11-2+deb11u2 2022.11-6+deb12u1 2024.11-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-28211.
The Tianocore EDK2 version 202008 is affected by this vulnerability.
The severity of this vulnerability is medium with a CVSS score of 6.7.
The CWE ID for this vulnerability is CWE-787 and CWE-122.
Yes, you can find more information about this vulnerability at the following link: https://bugzilla.tianocore.org/show_bug.cgi?id=1816