REDHAT-BUG-1694065: Medium severity edk ii vulnerability
Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.
Reference: https://edk2-docs.gitbooks.io/security-advisory/content/xhci-stack-local-stack-overflow.html
Upstream commits: https://github.com/tianocore/edk2/commit/acebdf14c985c5c9f50b37ece0b15ada87767359 https://github.com/tianocore/edk2/commit/72750e3bf9174f15c17e78f0f117b5e7311bb49f
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1694065?
The severity of REDHAT-BUG-1694065 is considered high due to the potential for denial of service by an unauthenticated user.
How do I fix REDHAT-BUG-1694065?
To fix REDHAT-BUG-1694065, update to the patched version of TianoCore EDK II that addresses the stack overflow vulnerability.
Who is affected by REDHAT-BUG-1694065?
Users running TianoCore EDK II are affected by REDHAT-BUG-1694065.
What kind of attack is associated with REDHAT-BUG-1694065?
REDHAT-BUG-1694065 is associated with a local denial of service attack due to stack overflow.
Is authentication required to exploit REDHAT-BUG-1694065?
No, authentication is not required to exploit REDHAT-BUG-1694065, making it particularly dangerous.