REDHAT-BUG-1858038: Medium severity tianocore edk ii vulnerability
Published Jul 16, 2020
·Updated
A flaw was found in edk2. Function GetEfiGlobalVariable2() return value is not checked possibly leading to secure boot bypass if an attacker can cause the API to fail.
References:
https://bugzilla.tianocore.org/showbug.cgi?id=2167
Affected Software
1 affected component
Tianocore edk2
Event History
Jul 16, 2020
Data Sourced
via Red Hat·08:59 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1858038?
The severity of REDHAT-BUG-1858038 is high due to the potential for secure boot bypass.
2
How do I fix REDHAT-BUG-1858038?
To fix REDHAT-BUG-1858038, ensure that the return values from the GetEfiGlobalVariable2() function are properly checked in the code.
3
Who is affected by REDHAT-BUG-1858038?
Users of the TianoCore edk2 firmware are affected by REDHAT-BUG-1858038.
4
What could an attacker achieve by exploiting REDHAT-BUG-1858038?
An attacker could exploit REDHAT-BUG-1858038 to bypass secure boot mechanisms.
5
Is there a workaround for REDHAT-BUG-1858038?
Currently, there are no documented workarounds for REDHAT-BUG-1858038, and it is advisable to apply patches as they become available.