---
id: CVE-2026-6862
title: 'A flaw was found in libefiboot, a component of efivar'
summary: >-
  A flaw was found in libefiboot, a component of efivar. The device path node
  parser in libefiboot fails to validate that each node's Length field is at
  least 4 bytes, which is the minimum size for an EFI (Extensible Firmware
  Interface) de…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-674
vendor: ubuntu
product: libefiboot
affected:
  - libefiboot
published: '2026-04-22'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T18:17:10.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6862'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:69321'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-6862'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2459982'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6862.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-6862'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6862'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00166
epssPercentile: 0.05171
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-04-22T14:28:03.007164Z'
ingestedAt: '2026-09-21T11:35:54.437Z'
patched:
  - hardened_images
---

## Overview

A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI (Extensible Firmware Interface) device path node header. A local user could exploit this vulnerability by providing a specially crafted device path node. This can lead to infinite recursion, causing stack exhaustion and a process crash, resulting in a denial of service (DoS).

## Affected

- `libefiboot`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Hardened Images · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6862.json)
- **RHSA-2026:69321** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69321)
