CVE-2022-36765: Integer Overflow in CreateHob
EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36765?
CVE-2022-36765 has a critical severity rating due to the potential for integrity, confidentiality, and availability compromise.
How do I fix CVE-2022-36765?
To fix CVE-2022-36765, upgrade to the affected software versions provided by your OS vendor, such as EDK2 versions 2022.11-6+deb12u1 or later.
What systems are affected by CVE-2022-36765?
CVE-2022-36765 affects multiple versions of the Tianocore EDK2 and specific packages in Ubuntu and Debian distributions.
Can CVE-2022-36765 be exploited remotely?
Yes, CVE-2022-36765 can be exploited via a local network, allowing attackers to potentially execute malicious code.
What is the impact of successfully exploiting CVE-2022-36765?
Successful exploitation of CVE-2022-36765 may lead to unauthorized access and manipulation of system data, affecting the overall system security.