---
id: CVE-2026-54334
title: >-
  UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures
  including volumes, file systems, and files
summary: >-
  UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures
  including volumes, file systems, and files. Prior to 1.14, ReadCLen() in
  uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd,
  CBIT) with CBIT …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: theopolis
product: uefi-firmware-parser
affected:
  - uefi-firmware-parser < 1.14
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:17:19.577'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54334'
references:
  - url: >-
      https://github.com/theopolis/uefi-firmware-parser/commit/bf3dfaa8a05675bae6ea0cbfa082ddcebfcde23e
    label: security-advisories@github.com
  - url: 'https://github.com/theopolis/uefi-firmware-parser/pull/145'
    label: security-advisories@github.com
  - url: 'https://github.com/theopolis/uefi-firmware-parser/releases/tag/v1.14'
    label: security-advisories@github.com
  - url: >-
      https://github.com/theopolis/uefi-firmware-parser/security/advisories/GHSA-hm2w-vr2p-hq7w
    label: security-advisories@github.com
  - url: 'https://github.com/theopolis/uefi-firmware-parser'
tags:
  - nvd
  - cve.org
  - osv
  - pip
epss: 0.00801
epssPercentile: 0.5471
aliases:
  - GHSA-hm2w-vr2p-hq7w
ecosystem: pip
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-16T18:35:51.342560Z'
ingestedAt: '2026-07-08T18:25:50.271Z'
---

## Overview

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT = 9 and can obtain 511 entries for the 510-element Sd->mCLen heap array because its loop does not enforce Index < NC. The CharC == 2 run-length path can additionally request up to 531 zero writes through Sd->mCLen[Index++] = 0. The normal CompressedSection.process() to efi_compressor.TianoDecompress() to TianoDecompress() to DecodeC() to ReadCLen() parsing path therefore permits crafted Tiano or EFI compressed firmware to corrupt heap memory, deterministically crash the parsing process, and potentially execute code depending on build and runtime details. This issue is fixed in version 1.14.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-54334)

Affected packages:

- `uefi-firmware <= 1.12`

Source: https://osv.dev/vulnerability/GHSA-hm2w-vr2p-hq7w
