REDHAT-BUG-2257582: Buffer Overflow
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
https://github.com/tianocore/edk2/security/advisories/GHSA-xvv8-66cq-prwr
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2257582?
The severity of REDHAT-BUG-2257582 is critical due to the potential for a heap buffer overflow that can compromise confidentiality, integrity, and availability.
How do I fix REDHAT-BUG-2257582?
To fix REDHAT-BUG-2257582, update to the latest version of TianoCore EDK2 that addresses this vulnerability.
What causes the vulnerability REDHAT-BUG-2257582?
The vulnerability REDHAT-BUG-2257582 is caused by a heap buffer overflow in the Tcg2MeasureGptTable() function.
Can REDHAT-BUG-2257582 be exploited remotely?
Yes, REDHAT-BUG-2257582 can potentially be exploited via a local network by an attacker.
What impact does REDHAT-BUG-2257582 have on my system?
The impact of REDHAT-BUG-2257582 can include compromised confidentiality, integrity, and availability of the affected system.