TianoCore EDK2
cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*, +1 more
- <= 202502
A vulnerability in the EDK2 HashPeImageByType function allows for an out-of-bounds read. This issue arises when a corrupted data pointer and length are sent via an adjacent network, potentially leading to a loss of integrity and availability. The vulnerability is present in the SecurityPkg component of EDK2, affecting versions through 202502.
Exploitation of this vulnerability could result in an out-of-bounds read, which may be leveraged to read sensitive information or cause a denial-of-service condition.
The vulnerability has been patched, and the patch is being upstreamed into EDK2. It is expected to be included in the May 2025 stable release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.