1sealsemantic last-mile verification

Research / Finding

UEFI firmware parser: ReadCLen heap write

F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003

Read the full technical write-up →

Root cause, affected code and disclosure timeline.

At a glance

Conditions
Parsing an untrusted firmware image can reach out-of-bounds writes in MakeTable or ReadCLen.
What to do
Check the installed package for the linked Tiano bounds checks. Release metadata conflicts: CVE records name 1.14; repository advisories name 1.13. Do not resolve that discrepancy from the version number alone.

1seal reading guide, reviewed 2026-09-25 against the linked records. Not a new vendor assessment or a device rollout check.

Fix and severity by source
  • CVE-2026-54334 (upstream record)Source observed: 2026-09-23

    Fix / version: CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
    Severity: 9.8 / 10; CVSS 3.1

  • 1SEAL-2026-010 (1seal assessment)Write-up dated: 2026-03-29

    Fix / version: CVE records: 1.14; repository GHSAs: 1.13 (conflicting version metadata)
    Severity: critical; numeric score not recorded

Source assessments remain separate. Different CVSS versions are not a revision of one another. Code fixes, released versions and deployed updates are distinct evidence.

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

9.8critical
CVE-2026-54334CVEtheopolis/uefi-firmware-parser

Heap out-of-bounds write in tiano decompressor `ReadCLen`

Fixed in: CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)

patched
details
Finding IDs
F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003
CVE
CVE-2026-54334
GHSA
GHSA-hm2w-vr2p-hq7w
Status
patched
Fixed in
CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
Recorded credit
reporter: @1seal
Note
PR #145 · fix commit bf3dfaa8a05675bae6ea0cbfa082ddcebfcde23e. CVE-2026-54334: GitHub_M CNA record verified PUBLISHED on 2026-09-23; CVE publication 2026-09-14. The CNA record and repository GHSA disagree on the patched version; neither is silently substituted for the other.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE registry state
PUBLISHED
CVE state checked
Upstream title
Heap out-of-bounds write in tiano decompressor `ReadCLen`
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
@1seal: finder (accepted)

F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003: Memory safety. Tiano ReadCLen writes outside the intended buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003

Security area (1seal assessment): Memory safety. Tiano ReadCLen writes outside the intended buffer. Reviewed 24 Sep 2026.

—score not recorded
1SEAL-2026-0101SEAL advisorytheopolis/uefi-firmware-parser

Two critical out-of-bounds writes in the imported Tiano decompressor

Fixed in: CVE records: 1.14; repository GHSAs: 1.13 (conflicting version metadata)

Fix recordednot counted
details
Finding IDs
F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003 / F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002
CVE
CVE-2026-54333 / CVE-2026-54334
Status
patched
CWE
CWE-787
Fixed in
CVE records: 1.14; repository GHSAs: 1.13 (conflicting version metadata)
Disclosure date
Note
Subsequent CVEs verified PUBLISHED on 2026-09-23: MakeTable is CVE-2026-54333; ReadCLen is CVE-2026-54334. The original write-up retains its dated observations.
Recorded severity
critical

F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003: Memory safety. Tiano ReadCLen writes outside the intended buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003

F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002: Memory safety. Tiano MakeTable writes outside the intended buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002

Security area (1seal assessment): Memory safety. Tiano ReadCLen writes outside the intended buffer. Tiano MakeTable writes outside the intended buffer. Reviewed 24 Sep 2026.

—score not recorded
theopolis/uefi-firmware-parser #145Credited fixtheopolis/uefi-firmware-parser

Apply hardening fixes from upstream Tiano implementation

merged
details
Finding IDs
F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003 / F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002
CVE
CVE-2026-54334 / CVE-2026-54333
Status
merged
Recorded credit
PR body: "Thank you @1seal for mentioning this!"
Note
PR #145 includes both ReadCLen and MakeTable bounds checks. Public mapping rechecked 2026-09-25: GHSA-hm2w-vr2p-hq7w / CVE-2026-54334 (ReadCLen) and GHSA-2689-5p89-6j3j / CVE-2026-54333 (MakeTable). One shared fix record, not two additional findings.

F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003: Memory safety. Tiano ReadCLen writes outside the intended buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003

F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002: Memory safety. Tiano MakeTable writes outside the intended buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002

Security area (1seal assessment): Memory safety. Tiano ReadCLen and MakeTable write outside their intended buffers. Reviewed 24 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.