Back

HIGH

Heap Buffer Overflow in Tcg2MeasurePeImage

Published Jan 9, 2024

Description

EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

Affected products

Remediation

Red Hat statement

Red Hat has protection mechanisms in place against buffer overflows, such as FORTIFY_SOURCE, Position Independent Executables or Stack Smashing Protection.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TianoCore
Published Jan 9, 2024
Updated Nov 3, 2025
Reserved Jul 25, 2022
CISA Vulnrichment
Updated Mar 6, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 9, 2024