CVE-2026-6862 is a validation flaw in libefiboot (part of the efivar package) where the device path node parser fails to validate minimum length requirements for EFI device path node headers. A local attacker can supply a maliciously crafted device path to trigger infinite recursion, leading to stack exhaustion and process denial of service. The vulnerability has a CVSS score of 5.5 (MEDIUM) with a local attack vector requiring no privileges but user interaction. The impact is limited to availability; there is no risk to confidentiality or integrity. The attack surface is restricted to systems where a local user can interact with the affected component. Exploitation status indicators suggest this vulnerability is not currently being actively exploited. It does not appear on the Known Exploited Vulnerabilities (KEV) catalog, is not on any active hot list, and has minimal community attention based on EPSS scoring. No publicly available exploit code has been widely distributed at this time, though the relatively straightforward nature of the flaw suggests proof-of-concept development would be feasible for researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ubuntu:libefiboot:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.