First published: Thu Aug 05 2021(Updated: )
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
Credit: infosec@edk2.groups.io
Affected Software | Affected Version | How to fix |
---|---|---|
Tianocore EDK II |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-28216.
The severity of CVE-2021-28216 is high.
The affected software is Tianocore Edk Ii.
It is recommended to set PcdFirmwarePerformanceDataTableS3Support to FALSE.
You can find more information about CVE-2021-28216 at this link: https://bugzilla.tianocore.org/show_bug.cgi?id=2957