EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4207-1 | edk2 security update |
Debian DSA |
DSA-5624-1 | edk2 security update |
EUVD |
EUVD-2022-39465 | EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. |
Ubuntu USN |
USN-6638-1 | EDK II vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Nov 2025 05:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 04 Jun 2025 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Feb 2025 01:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. | EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TianoCore
Published:
Updated: 2025-11-03T19:27:16.178Z
Reserved: 2022-07-25T19:43:11.215Z
Link: CVE-2022-36765
Updated: 2025-11-03T19:27:16.178Z
Status : Modified
Published: 2024-01-09T16:15:43.500
Modified: 2025-11-03T20:15:55.290
Link: CVE-2022-36765
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN