A stack buffer overflow was found in edk2 when the HII database contains a Bitmap who claims as 4-bit or 8-bit per pixel, but the palette contains more than 16(2^4) or 256(2^8) colors.
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1686785]
Affects: fedora-all [bug 1686784]
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2125 https://access.redhat.com/errata/RHSA-2019:2125
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):