Back

HIGH

Integer Overflow in CreateHob

Published Jan 9, 2024

Description

EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

Affected products

Remediation

Red Hat statement

Red Hat has protection mechanisms in place against buffer overflows, such as FORTIFY_SOURCE, Position Independent Executables or Stack Smashing Protection.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TianoCore
Published Jan 9, 2024
Updated Nov 3, 2025
Reserved Jul 25, 2022
CISA Vulnrichment
Updated May 8, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 9, 2024