Description
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read from a crafted Tiano or EFI compressed firmware bitstream remain within the expected range from 0 through 16. The normal CompressedSection.process() to efi_compressor.TianoDecompress() to TianoDecompress() to ReadPTLen() to MakeTable() parsing path can consequently write beyond the stack-allocated Count[17] array and related decode tables. The resulting stack corruption deterministically crashes the parsing process and may permit code execution depending on build and runtime details. This issue is fixed in version 1.14.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The UEFI Firmware Parser processes BIOS, Intel ME, and UEFI images. It contains a stack‑out‑of‑bounds write flaw in the MakeTable function when handling Tiano or EFI compressed firmware. The parser does not validate that bit‑length values from a compressed stream are between 0 and 16; as a result it writes past the Count[17] array, corrupting the stack. The overflow deterministically crashes the parser and, depending on the build and runtime, may allow arbitrary code execution, a classic stack buffer overflow identified as CWE‑787.

Affected Systems

The theopolis:uefi‑firmware‑parser library, used in UEFI firmware parsing tools, is affected for all released versions prior to 1.14. Systems or services that embed this library, such as firmware analysis applications, forensics workflows, or any process parsing BIOS, Intel ME, or UEFI images, are at risk. The vulnerability resides in the open‑source project and can impact both local deployments and integrated components in larger system environments.

Risk and Exploitability

The CVSS score of 9.8 denotes a critical severity. The EPSS score of < 1% indicates a very low exploitation probability, but the CVSS score of 9.8 implies a critical impact. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a crafted compressed firmware stream to a vulnerable instance of the parser, which could be achieved through an untrusted file upload or a compromised build pipeline. The stack corruption could result in a crash or potentially enable code execution depending on binary layout and runtime details.

Generated by OpenCVE AI on September 20, 2026 at 22:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the uefi‑firmware‑parser library to version 1.14 or fix.
  • Update all systems that invoke the parser to use the patched version, including any automated build or analysis pipelines that ingest, restrict the parser to handle only trusted firmware files and disable it for untrusted inputs to prevent exploitation.
  • Run the parser in a sandboxed or restricted environment to limit potential damage from a crash or code execution.

Generated by OpenCVE AI on September 20, 2026 at 22:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2689-5p89-6j3j UEFI Firmware Parser has a stack out-of-bounds write in tiano decompressor MakeTable
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Theopolis
Theopolis uefi-firmware-parser
Vendors & Products Theopolis
Theopolis uefi-firmware-parser

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read from a crafted Tiano or EFI compressed firmware bitstream remain within the expected range from 0 through 16. The normal CompressedSection.process() to efi_compressor.TianoDecompress() to TianoDecompress() to ReadPTLen() to MakeTable() parsing path can consequently write beyond the stack-allocated Count[17] array and related decode tables. The resulting stack corruption deterministically crashes the parsing process and may permit code execution depending on build and runtime details. This issue is fixed in version 1.14.
Title UEFI Firmware Parser: Stack out-of-bounds write in tiano decompressor MakeTable
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Theopolis Uefi-firmware-parser
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:55:32.815Z

Reserved: 2026-06-12T19:23:22.316Z

Link: CVE-2026-54333

cve-icon Vulnrichment

Updated: 2026-09-15T13:30:41.309Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:45.990

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses