Skip to content

Commit 8f6d343

Browse files
Douglas Flick [MSFT]mergify[bot]
Douglas Flick [MSFT]
authored andcommitted
SecurityPkg: : Adding CVE 2022-36764 to SecurityFixes.yaml
This creates / adds a security file that tracks the security fixes found in this package and can be used to find the fixes that were applied. Cc: Jiewen Yao <[email protected]> Signed-off-by: Doug Flick [MSFT] <[email protected]> Reviewed-by: Jiewen Yao <[email protected]>
1 parent 0d341c0 commit 8f6d343

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

SecurityPkg/SecurityFixes.yaml

+14
Original file line numberDiff line numberDiff line change
@@ -20,3 +20,17 @@ CVE_2022_36763:
2020
- https://bugzilla.tianocore.org/show_bug.cgi?id=4117
2121
- https://bugzilla.tianocore.org/show_bug.cgi?id=2168
2222
- https://bugzilla.tianocore.org/show_bug.cgi?id=1990
23+
CVE_2022_36764:
24+
commit_titles:
25+
- "SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4118 - CVE 2022-36764"
26+
- "SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4118 - CVE 2022-36764"
27+
- "SecurityPkg: : Adding CVE 2022-36764 to SecurityFixes.yaml"
28+
cve: CVE-2022-36764
29+
date_reported: 2022-10-25 12:23 UTC
30+
description: Heap Buffer Overflow in Tcg2MeasurePeImage()
31+
note:
32+
files_impacted:
33+
- Library\DxeTpm2MeasureBootLib\DxeTpm2MeasureBootLib.c
34+
- Library\DxeTpmMeasureBootLib\DxeTpmMeasureBootLib.c
35+
links:
36+
- https://bugzilla.tianocore.org/show_bug.cgi?id=4118

0 commit comments

Comments
 (0)