PT-2024-1803 · Edk2+11 · Edk2+11

Xvl00Per

·

Published

2024-01-09

·

Updated

2026-01-22

·

CVE-2022-36765

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EDK2 (affected versions not specified)
Description The issue is related to the CreateHob() function in EDK2, which is susceptible to an integer overflow that can lead to a buffer overflow. This can be triggered via a local network, potentially compromising confidentiality, integrity, and/or availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2024:3017
ALSA-2024:4749
ALT-PU-2024-14732
ALT-PU-2024-14734
ALT-PU-2024-14950
AZL-38920
AZL-39424
AZL-39556
BDU:2024-01539
CESA-2024_3017
CVE-2022-36765
DLA-4207-1
DSA-5624-1
GHSA-CH4W-V7M3-G8WX
INFSA-2024_3017
INFSA-2024_4749
OESA-2024-1350
RHSA-2024:3017
RHSA-2024:4749
RHSA-2024_3017
RHSA-2024_4749
SUSE-SU-2026:0120-1
SUSE-SU-2026:0121-1
SUSE-SU-2026:0212-1
SUSE-SU-2026:0213-1
SUSE-SU-2026:20246-1
USN-6638-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Edk2
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu
Zvirt Node