Junglewise Threat Intelligence
theopolis uefi-firmware-parser heap out-of-bounds write in Tiano decompressor
Severity: critical · CVSS 9.8 · Published 2026-04-16
Technologies: Theopolis Uefi-Firmware-Parser, uefi-firmware (PyPI). Vendors: Theopolis, PyPI.
Executive brief
The uefi-firmware-parser library contains a heap out-of-bounds write vulnerability in its Tiano/EFI decompression engine. An attacker can exploit this by providing a malicious firmware image, potentially leading to arbitrary code execution or a denial-of-service crash.
Affected products
- theopolis uefi-firmware-parser
- PyPI uefi-firmware
Related threats
- UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen
- UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTabl
- theopolis uefi-firmware-parser stack out-of-bounds write in MakeTable