{"id":"UBUNTU-CVE-2026-6862","details":"A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI (Extensible Firmware Interface) device path node header. A local user could exploit this vulnerability by providing a specially crafted device path node. This can lead to infinite recursion, causing stack exhaustion and a process crash, resulting in a denial of service (DoS).","modified":"2026-05-26T19:29:36.071107617Z","published":"2026-04-22T14:17:00Z","upstream":["CVE-2026-6862"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-6862"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-6862"}],"affected":[{"package":{"name":"efivar","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/efivar?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.21-1~14.04.2"],"ecosystem_specific":{"binaries":[{"binary_name":"efivar","binary_version":"0.21-1~14.04.2"},{"binary_name":"libefivar0","binary_version":"0.21-1~14.04.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6862.json"}},{"package":{"name":"efivar","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/efivar?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.21-1","0.23-1","0.23-2"],"ecosystem_specific":{"binaries":[{"binary_name":"efivar","binary_version":"0.23-2"},{"binary_name":"libefivar0","binary_version":"0.23-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6862.json"}},{"package":{"name":"efivar","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/efivar?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["31-1","32-1","32-2","34-1"],"ecosystem_specific":{"binaries":[{"binary_name":"efivar","binary_version":"34-1"},{"binary_version":"34-1","binary_name":"libefiboot1"},{"binary_version":"34-1","binary_name":"libefivar1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6862.json"}},{"package":{"name":"efivar","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/efivar?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["37-2ubuntu2","37-2ubuntu2.1","37-2ubuntu2.2"],"ecosystem_specific":{"binaries":[{"binary_version":"37-2ubuntu2.2","binary_name":"efivar"},{"binary_name":"libefiboot1","binary_version":"37-2ubuntu2.2"},{"binary_name":"libefivar1","binary_version":"37-2ubuntu2.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6862.json"}},{"package":{"name":"efivar","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/efivar?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["37-6ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"efivar","binary_version":"37-6ubuntu2"},{"binary_name":"libefiboot1","binary_version":"37-6ubuntu2"},{"binary_version":"37-6ubuntu2","binary_name":"libefivar1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6862.json"}},{"package":{"name":"efivar","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/efivar?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["37-6ubuntu3","38-3","38-3.1","38-3.1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"38-3.1build1","binary_name":"efivar"},{"binary_version":"38-3.1build1","binary_name":"libefiboot1t64"},{"binary_name":"libefisec1t64","binary_version":"38-3.1build1"},{"binary_version":"38-3.1build1","binary_name":"libefivar1t64"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6862.json"}},{"package":{"name":"efivar","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/efivar?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["38-3.1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"efivar","binary_version":"38-3.1build1"},{"binary_name":"libefiboot1t64","binary_version":"38-3.1build1"},{"binary_name":"libefisec1t64","binary_version":"38-3.1build1"},{"binary_name":"libefivar1t64","binary_version":"38-3.1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6862.json"}},{"package":{"name":"efivar","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/efivar?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["38-3.1build1","39-2"],"ecosystem_specific":{"binaries":[{"binary_name":"efivar","binary_version":"39-2"},{"binary_version":"39-2","binary_name":"libefiboot1t64"},{"binary_name":"libefisec1t64","binary_version":"39-2"},{"binary_version":"39-2","binary_name":"libefivar1t64"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6862.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}