CVE-2026-34963 | Barebox up to 2026.04.0 EFI PE Loader efi/loader/pe.c VirtualAddress/size integer overflow (EUVD-2026-29347)
A vulnerability labeled as problematic has been found in Barebox up to 2026.04.0. Affected by this issue is some unknown functionality of the file efi/loader/pe.c of the component EFI PE Loader. Such manipulation of the argument VirtualAddress/size leads to integer overflow.
This vulnerability is uniquely identified as CVE-2026-34963. Local access is required to approach this attack. No exploit exists.
The affected component should be upgraded.