diff options
author | Dandan Bi <dandan.bi@intel.com> | 2019-09-24 11:17:52 +0800 |
---|---|---|
committer | mergify[bot] <37929162+mergify[bot]@users.noreply.github.com> | 2020-02-14 08:02:07 +0000 |
commit | c32be82e99ef272e7fa742c2f06ff9a4c3756613 (patch) | |
tree | 73e11e2840d16635bc55ec381f07c8596c792200 /BaseTools/Source/Python/Table/TableQuery.py | |
parent | f9713abe950b3d3e0e27bf87a03b5fa2bc69735f (diff) | |
download | edk2-c32be82e99ef272e7fa742c2f06ff9a4c3756613.tar.gz edk2-c32be82e99ef272e7fa742c2f06ff9a4c3756613.tar.bz2 edk2-c32be82e99ef272e7fa742c2f06ff9a4c3756613.zip |
MdeModulePkg/HiiDB: Remove configuration table when it's freed (CVE-2019-14586)
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=1995
Fix the corner case issue that the original configuration runtime
memory is freed, but it is still exposed to the OS runtime.
So this patch is to remove the configuration table to avoid being
used in OS runtime when the configuration runtime memory is freed.
Cc: Liming Gao <liming.gao@intel.com>
Cc: Eric Dong <eric.dong@intel.com>
Cc: Jian J Wang <jian.j.wang@intel.com>
Signed-off-by: Dandan Bi <dandan.bi@intel.com>
Reviewed-by: Eric Dong <eric.dong@intel.com>
Reviewed-by: Jian J Wang <jian.j.wang@intel.com>
Diffstat (limited to 'BaseTools/Source/Python/Table/TableQuery.py')
0 files changed, 0 insertions, 0 deletions