CVE-2022-36763

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-36763
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-36763.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-36763
Downstream
Related
Published
2024-01-09T16:15:43Z
Modified
2025-10-08T05:15:55.238586Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

References

Affected packages

Git / github.com/tianocore/edk2

Affected ranges

Type
GIT
Repo
https://github.com/tianocore/edk2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other

edk2-stable201808
edk2-stable201811
edk2-stable201903
edk2-stable201905
edk2-stable201908
edk2-stable201911
edk2-stable202002
edk2-stable202005
edk2-stable202008
edk2-stable202011
edk2-stable202102
edk2-stable202105
edk2-stable202108
edk2-stable202108-rc0
edk2-stable202108-rc1
edk2-stable202111
edk2-stable202111-rc1
edk2-stable202202
edk2-stable202202-rc1
edk2-stable202205
edk2-stable202205-rc1
edk2-stable202208
edk2-stable202211
edk2-stable202302
edk2-stable202305
edk2-stable202308
edk2-stable202311