Impact
The UEFI Firmware Parser processes BIOS, Intel ME, and UEFI images. It contains a stack‑out‑of‑bounds write flaw in the MakeTable function when handling Tiano or EFI compressed firmware. The parser does not validate that bit‑length values from a compressed stream are between 0 and 16; as a result it writes past the Count[17] array, corrupting the stack. The overflow deterministically crashes the parser and, depending on the build and runtime, may allow arbitrary code execution, a classic stack buffer overflow identified as CWE‑787.
Affected Systems
The theopolis:uefi‑firmware‑parser library, used in UEFI firmware parsing tools, is affected for all released versions prior to 1.14. Systems or services that embed this library, such as firmware analysis applications, forensics workflows, or any process parsing BIOS, Intel ME, or UEFI images, are at risk. The vulnerability resides in the open‑source project and can impact both local deployments and integrated components in larger system environments.
Risk and Exploitability
The CVSS score of 9.8 denotes a critical severity. The EPSS score of < 1% indicates a very low exploitation probability, but the CVSS score of 9.8 implies a critical impact. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a crafted compressed firmware stream to a vulnerable instance of the parser, which could be achieved through an untrusted file upload or a compromised build pipeline. The stack corruption could result in a crash or potentially enable code execution depending on binary layout and runtime details.
OpenCVE Enrichment
Github GHSA