Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade edk2 | Apr 30, 2021 | Nov 23, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 23, 2020 |
| Suse | — | Upgrade ovmfUpgrade qemu-uefi-aarch64Upgrade qemu-ovmf-x86_64-debugUpgrade qemu-ovmf-ia32Upgrade qemu-ovmf-x86_64Upgrade ovmf-tools | Sep 23, 2020 | Sep 21, 2020 |
| Ubuntu | — | Upgrade qemu-efiUpgrade qemu-efi-armUpgrade qemu-efi-aarch64Upgrade ovmf | Jan 8, 2021 | Sep 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub