Impact
The UEFI Firmware Parser processes BIOS, Intel ME, and UEFI firmware and files. In all versions before 1.14, the ReadCLen() routine in the Tiano decompressor reads a 9‑bit number using GetBits and can produce up to 511 entries in the 510‑element Sd->mCLen heap array because the loop does not enforce an Index < NC bound. When CharC == 2 run, up to 531 zero writes may also occur into the same buffer via Sd->mCLen[Index++] = 0. As the normal CompressedSection.process() → efi_compressor.TianoDecompress() → TianoDecompress() → DecodeC() → ReadCLen() parsing path consumes the data, a crafted Tiano or EFI‑compressed firmware image can corrupt heap memory, deterministically crash the parsing process, and, depending on build and runtime details, potentially execute arbitrary code. The flaw is fixed in version 1.14.
Affected Systems
The issue affects theopolis’ UEFI Firmware Parser library released under the name theopolis:uefi-firmware-parser. All versions before 1.14 are vulnerable; the vulnerability is confined to the library itself and is not tied to any particular operating system or firmware platform.
Risk and Exploitability
The CVSS score of 9.8 classifies the flaw as critical, and with an EPSS score of less than 1 % the probability of exploitation is considered very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker supplying a crafted Tiano or EFI‑compressed the parser. If the parser processes such malicious input, it may crash or, in some build contexts, execute arbitrary code. Because the flaw is in a library used only when firmware is parsed, risk is limited to environments that routinely process untrusted firmware files; otherwise the threat remains theoretical.
OpenCVE Enrichment
Github GHSA