Re: [edk2-devel] [patch] MdeModulePkg/HiiDB: Remove configuration table when it's freed (CVE-2019-14586)

2020-02-12 Thread Wang, Jian J
Reviewed-by: Jian J Wang Regards, Jian > -Original Message- > From: Bi, Dandan > Sent: Thursday, February 13, 2020 12:03 PM > To: devel@edk2.groups.io > Cc: Gao, Liming ; Dong, Eric ; > Wang, Jian J > Subject: [patch] MdeModulePkg/HiiDB: Remove configuration table when it's > freed

[edk2-devel] [patch] MdeModulePkg/HiiDB: Remove configuration table when it's freed (CVE-2019-14586)

2020-02-12 Thread Dandan Bi
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=1995 Fix the corner case issue that the original configuration runtime memory is freed, but it is still exposed to the OS runtime. So this patch is to remove the configuration table to avoid being used in OS runtime when the configuration