Description
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT = 9 and can obtain 511 entries for the 510-element Sd->mCLen heap array because its loop does not enforce Index < NC. The CharC == 2 run-length path can additionally request up to 531 zero writes through Sd->mCLen[Index++] = 0. The normal CompressedSection.process() to efi_compressor.TianoDecompress() to TianoDecompress() to DecodeC() to ReadCLen() parsing path therefore permits crafted Tiano or EFI compressed firmware to corrupt heap memory, deterministically crash the parsing process, and potentially execute code depending on build and runtime details. This issue is fixed in version 1.14.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Heap out‑of‑bounds write that can crash or enable code execution
Action: Immediate Patch
AI Analysis

Impact

The UEFI Firmware Parser processes BIOS, Intel ME, and UEFI firmware and files. In all versions before 1.14, the ReadCLen() routine in the Tiano decompressor reads a 9‑bit number using GetBits and can produce up to 511 entries in the 510‑element Sd->mCLen heap array because the loop does not enforce an Index < NC bound. When CharC == 2 run, up to 531 zero writes may also occur into the same buffer via Sd->mCLen[Index++] = 0. As the normal CompressedSection.process() → efi_compressor.TianoDecompress() → TianoDecompress() → DecodeC() → ReadCLen() parsing path consumes the data, a crafted Tiano or EFI‑compressed firmware image can corrupt heap memory, deterministically crash the parsing process, and, depending on build and runtime details, potentially execute arbitrary code. The flaw is fixed in version 1.14.

Affected Systems

The issue affects theopolis’ UEFI Firmware Parser library released under the name theopolis:uefi-firmware-parser. All versions before 1.14 are vulnerable; the vulnerability is confined to the library itself and is not tied to any particular operating system or firmware platform.

Risk and Exploitability

The CVSS score of 9.8 classifies the flaw as critical, and with an EPSS score of less than 1 % the probability of exploitation is considered very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker supplying a crafted Tiano or EFI‑compressed the parser. If the parser processes such malicious input, it may crash or, in some build contexts, execute arbitrary code. Because the flaw is in a library used only when firmware is parsed, risk is limited to environments that routinely process untrusted firmware files; otherwise the threat remains theoretical.

Generated by OpenCVE AI on September 20, 2026 at 22:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the UEFI Firmware Parser to version 1.14 from trusted sources immediately.
  • If the update cannot be applied right away, run the parser in a sandboxed or isolated environment to contain any potential impact.
  • Monitor application logs or crash reports for indications of parser failures or abnormal memory corruption and investigate any suspicious events.

Generated by OpenCVE AI on September 20, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hm2w-vr2p-hq7w UEFI Firmware Parser has a heap out-of-bounds write in tiano decompressor ReadCLen
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Theopolis
Theopolis uefi-firmware-parser
Vendors & Products Theopolis
Theopolis uefi-firmware-parser

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT = 9 and can obtain 511 entries for the 510-element Sd->mCLen heap array because its loop does not enforce Index < NC. The CharC == 2 run-length path can additionally request up to 531 zero writes through Sd->mCLen[Index++] = 0. The normal CompressedSection.process() to efi_compressor.TianoDecompress() to TianoDecompress() to DecodeC() to ReadCLen() parsing path therefore permits crafted Tiano or EFI compressed firmware to corrupt heap memory, deterministically crash the parsing process, and potentially execute code depending on build and runtime details. This issue is fixed in version 1.14.
Title UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen`
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Theopolis Uefi-firmware-parser
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:35:59.871Z

Reserved: 2026-06-12T19:23:22.316Z

Link: CVE-2026-54334

cve-icon Vulnrichment

Updated: 2026-09-16T18:35:56.481Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:46.143

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses