A flaw was found in edk2 in the decompression process of UEFI images in the LzmaUefiDecompressGetInfo() function. A crafted LZMA header can lead to a heap-based buffer overflow.
Upstream patch is ready and has been reviewed:
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1899496]
Affects: fedora-all [bug 1899495]
Upstream fix merged as commit e7bd0dd26db7, via <https://github.com/tianocore/edk2/pull/1138>.
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2021:2591 https://access.redhat.com/errata/RHSA-2021:2591
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):