Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade edk2 | Apr 30, 2021 | Nov 23, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 23, 2020 |
| Suse | — | Upgrade qemu-uefi-aarch64Upgrade qemu-ovmf-x86_64-debugUpgrade ovmfUpgrade ovmf-toolsUpgrade qemu-ovmf-x86_64Upgrade qemu-ovmf-ia32 | Sep 23, 2020 | Sep 21, 2020 |
| Ubuntu | — | Upgrade qemu-efiUpgrade qemu-efi-aarch64Upgrade ovmfUpgrade qemu-efi-arm | Jan 8, 2021 | Sep 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub