REDHAT-BUG-1683372: High severity tianocore edk ii vulnerability
A flaw was found in edk2. When registering a Ram disk whose size is not a multiple of 512 bytes, the BlockIo protocol produced by the RamDiskDxe driver will incur memory read/write overrun. The memory overrun will happen when reading/writing the last block on the Ram disk.
Upstream Bug: https://bugzilla.tianocore.org/showbug.cgi?id=1134
Upstream Patch: https://lists.01.org/pipermail/edk2-devel/2019-February/037248.html https://lists.01.org/pipermail/edk2-devel/2019-February/037249.html https://lists.01.org/pipermail/edk2-devel/2019-February/037250.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1683372?
The severity of REDHAT-BUG-1683372 is considered high due to the potential for memory read/write overrun.
How do I fix REDHAT-BUG-1683372?
To fix REDHAT-BUG-1683372, ensure that Ram disks are registered with sizes that are multiples of 512 bytes.
What impact does REDHAT-BUG-1683372 have on systems?
REDHAT-BUG-1683372 can lead to serious data corruption or system instability caused by memory overruns.
Which software is affected by REDHAT-BUG-1683372?
The vulnerability REDHAT-BUG-1683372 affects the TianoCore EDK II software when handling improperly sized Ram disks.
Is there a workaround for REDHAT-BUG-1683372?
Currently, the best workaround for REDHAT-BUG-1683372 is to avoid using Ram disks with sizes that are not multiples of 512 bytes.