HIGH
Heap Buffer Overflow in Tcg2MeasurePeImage
Published Jan 9, 2024
7.8
HIGHCVSS 3.1
EPSS 0.29%
Description
EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
Affected products
-
- Version -StatusaffectedConstraints<=202311
- Version
No data.
Red Hat Enterprise Linux 8
edk2-0:20220126gitbb1bba3d77-13.el8_10
Fixed · RHSA-2024:3017
Red Hat Enterprise Linux 9
edk2-0:20231122-6.el9
Fixed · RHSA-2024:2264
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | edk2-0:20220126gitbb1bba3d77-13.el8_10 | Fixed | RHSA-2024:3017 |
| Red Hat Enterprise Linux 9 | edk2-0:20231122-6.el9 | Fixed | RHSA-2024:2264 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat has protection mechanisms in place against buffer overflows, such as FORTIFY_SOURCE, Position Independent Executables or Stack Smashing Protection.
Weaknesses (3)
References (7)
- https://access.redhat.com/security/cve/CVE-2022-36764 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2257583 Issue Tracking
- https://github.com/tianocore/edk2/security/advisories/GHSA-4hcq-p8q8-hj8j Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/06/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SJ42V7O7F4OU6R7QSQQECLB6LDHKZIMQ/
- https://nvd.nist.gov/vuln/detail/CVE-2022-36764
- https://www.cve.org/CVERecord?id=CVE-2022-36764
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TianoCore
Published Jan 9, 2024
Updated Nov 3, 2025
Reserved Jul 25, 2022
Link CVE-2022-36764
CISA Vulnrichment
Updated Mar 6, 2024