Root cause, affected code and disclosure timeline.
At a glance
Conditions
Parsing an untrusted firmware image can reach out-of-bounds writes in MakeTable or ReadCLen.
What to do
Check the installed package for the linked Tiano bounds checks. Release metadata conflicts: CVE records name 1.14; repository advisories name 1.13. Do not resolve that discrepancy from the version number alone.
1seal reading guide, reviewed 2026-09-25 against the linked records. Not a new vendor assessment or a device rollout check.
Fix / version: CVE records: 1.14; repository GHSAs: 1.13 (conflicting version metadata) Severity: critical; numeric score not recorded
Source assessments remain separate. Different CVSS versions are not a revision of one another. Code fixes, released versions and deployed updates are distinct evidence.
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Stack out-of-bounds write in tiano decompressor MakeTable
Fixed in: CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
patched
details
Finding IDs
F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002
CVE
CVE-2026-54333
GHSA
GHSA-2689-5p89-6j3j
Status
patched
Fixed in
CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
Recorded credit
reporter: @1seal
Note
PR #145 · fix commit bf3dfaa8a05675bae6ea0cbfa082ddcebfcde23e. CVE-2026-54333: GitHub_M CNA record verified PUBLISHED on 2026-09-23; CVE publication 2026-09-14. The CNA record and repository GHSA disagree on the patched version; neither is silently substituted for the other.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE registry state
PUBLISHED
CVE state checked
Upstream title
Stack out-of-bounds write in tiano decompressor MakeTable
Upstream CWE
CWE-787
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
@1seal: finder (accepted)
F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002: Memory safety. Tiano MakeTable writes outside the intended buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
CVE records: 1.14; repository GHSAs: 1.13 (conflicting version metadata)
Disclosure date
Note
Subsequent CVEs verified PUBLISHED on 2026-09-23: MakeTable is CVE-2026-54333; ReadCLen is CVE-2026-54334. The original write-up retains its dated observations.
Recorded severity
critical
F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003: Memory safety. Tiano ReadCLen writes outside the intended buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
PR #145 includes both ReadCLen and MakeTable bounds checks. Public mapping rechecked 2026-09-25: GHSA-hm2w-vr2p-hq7w / CVE-2026-54334 (ReadCLen) and GHSA-2689-5p89-6j3j / CVE-2026-54333 (MakeTable). One shared fix record, not two additional findings.
F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003: Memory safety. Tiano ReadCLen writes outside the intended buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.