Firmware extraction: sanitize partition, module and volume path components
Fixed in: Public fix committed 2026-06-04; first containing release not established
details
- Finding IDs
- F-UEFI-FIRMWARE-PATH-TRAVERSAL-001 / F-UEFI-FIRMWARE-PATH-TRAVERSAL-002
- Status
- fixed publicly
- Fixed in
- Public fix committed 2026-06-04; first containing release not established
- Recorded credit
- Public fix author: Teddy Reed. Public 1seal credit and a causal link to our report are not established.
- Note
- One shared public fix covers both report IDs: ME partition/manifest dump paths and firmware volume dump paths now use sanitized components. The patch also adds path containment tests. This records the matching extraction-path correction, not two independent fixes. Tiano decompression CVEs do not apply to this record; symlink-safe extraction is not claimed.
F-UEFI-FIRMWARE-PATH-TRAVERSAL-001: File / path escapes. Firmware-controlled path components can escape the intended extraction directory. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-UEFI-FIRMWARE-PATH-TRAVERSAL-001
F-UEFI-FIRMWARE-PATH-TRAVERSAL-002: File / path escapes. Firmware-controlled path components can escape the intended extraction directory. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-UEFI-FIRMWARE-PATH-TRAVERSAL-002
Security area (1seal assessment): Authorization. Firmware-controlled path components can escape the intended extraction directory. Reviewed 7 Oct 2026.