GPU VulnDB

Database/Firmware, BMC & network fabric

uefi-firmware-parser: unvalidated bit lengths in MakeTable() smash the stack on crafted firmware

CVSS 9.8CVE-2026-54333Firmware, BMC & network fabriccurated

Impact

MakeTable() in the Tiano decompressor does not check that bit-length values read from the compressed bitstream fall in the expected 0-16 range, so a crafted Tiano or EFI compressed section drives writes past the stack-allocated Count[17] array and the neighbouring decode tables. This matters to operators who parse firmware images they did not build - vendor BIOS/BMC bundles pulled into an automated validation, attestation or inventory pipeline. The parsing process crashes deterministically, and the advisory states code execution may be possible depending on build and runtime hardening; code execution would land in whatever account that pipeline runs as, typically one holding the firmware images for the whole fleet. Nothing here affects firmware on a running node - the exposure is the tooling, not the platform.

Who can reach it

Anyone who can get a crafted firmware image into a parsing run: an untrusted or tampered vendor blob, a file upload into a firmware analysis service, or any automated ingest of third-party images. No authentication is implied beyond the ability to supply the file.

What to do

Upgrade uefi-firmware-parser to 1.14, which adds the range check. This is a library bump plus a restart of whatever service or job imports it - no node, fleet or firmware action is involved. Until then, parse only images whose source you trust and run the parser in a sandbox with no access to firmware repositories or signing material.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.