edk2-ovmf

Direct Vulnerabilities

Known vulnerabilities in the edk2-ovmf package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
NULL Pointer Dereference

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Integer Overflow or Wraparound

*
  • L
Incorrect Calculation of Buffer Size

*
  • L
Improper Validation of Integrity Check Value

*
  • L
Integer Overflow or Wraparound

*
  • L
NULL Pointer Dereference

*
  • L
Information Exposure

*
  • L
Integer Overflow or Wraparound

*
  • M
Buffer Access with Incorrect Length Value

*
  • L
CVE-2026-28387

*
  • L
NULL Pointer Dereference

*
  • L
Improper Handling of Missing Special Element

*
  • M
NULL Pointer Dereference

*
  • L
Improper Validation of Specified Type of Input

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • L
Out-of-bounds Write

*
  • L
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • L
Improper Validation of Specified Quantity in Input

*
  • L
Missing Required Cryptographic Step

*
  • M
Information Exposure

*
  • H
Improper Input Validation

*
  • M
Out-of-bounds Write

<0:20220126gitbb1bba3d77-13.el8_10.10
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Write

*
  • L
Covert Timing Channel

*
  • M
Heap-based Buffer Overflow

<0:20220126gitbb1bba3d77-13.el8_10.4
  • L
Information Exposure

*
  • M
Divide By Zero

<0:20220126gitbb1bba3d77-13.el8_10.2
  • L
Resource Exhaustion

*
  • L
NULL Pointer Dereference

*
  • H
Out-of-Bounds

<0:20220126gitbb1bba3d77-6.el8_9.6
  • H
Out-of-bounds Read

<0:20220126gitbb1bba3d77-13.el8_10
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:20220126gitbb1bba3d77-13.el8_10
  • H
Out-of-Bounds

<0:20220126gitbb1bba3d77-13.el8_10
  • H
Out-of-bounds Read

<0:20220126gitbb1bba3d77-13.el8_10
  • H
Out-of-Bounds

<0:20220126gitbb1bba3d77-6.el8_9.6
  • M
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

<0:20220126gitbb1bba3d77-13.el8_10.2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:20220126gitbb1bba3d77-13.el8_10
  • M
Information Exposure

<0:20220126gitbb1bba3d77-13.el8_10.2
  • H
Integer Overflow to Buffer Overflow

<0:20220126gitbb1bba3d77-13.el8_10
  • H
Integer Overflow to Buffer Overflow

<0:20220126gitbb1bba3d77-13.el8_10
  • H
Integer Overflow to Buffer Overflow

<0:20220126gitbb1bba3d77-13.el8_10
  • L
Resource Exhaustion

<0:20220126gitbb1bba3d77-6.el8_9.3
  • L
Resource Exhaustion

*
  • H
Incorrect Type Conversion or Cast

<0:20220126gitbb1bba3d77-4.el8
  • H
Use After Free

<0:20220126gitbb1bba3d77-4.el8
  • H
Double Free

<0:20220126gitbb1bba3d77-4.el8
  • H
Information Exposure

<0:20220126gitbb1bba3d77-4.el8
  • M
Buffer Underflow

*
  • L
Improper Input Validation

*
  • H
Out-of-Bounds

<0:20200602gitca407c7246bf-4.el8_4.2
  • M
Buffer Overflow

<0:20200602gitca407c7246bf-4.el8_4.1
  • M
Integer Overflow or Wraparound

<0:20190829git37eef91017ad-9.el8
  • M
Buffer Overflow

<0:20190308git89910a39dcfd-6.el8
  • M
Out-of-bounds Write

<0:20190308git89910a39dcfd-6.el8
  • M
Stack-based Buffer Overflow

<0:20190308git89910a39dcfd-6.el8
  • M
Resource Exhaustion

<0:20200602gitca407c7246bf-3.el8
  • H
Buffer Access with Incorrect Length Value

<0:20180508gitee3198e672e2-9.el8_0.1
  • M
Uncontrolled Recursion

<0:20210527gite1999b264f1f-3.el8
  • M
Integer Overflow or Wraparound

<0:20210527gite1999b264f1f-3.el8
  • M
NULL Pointer Dereference

<0:20210527gite1999b264f1f-3.el8
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Incorrect Authorization

*
  • M
NULL Pointer Dereference

<0:20210527gite1999b264f1f-3.el8