CVE-2026-24795 | CloverHackyColor CloverBootloader prior 5162 Oniguruma out-of-bounds write (EUVD-2026-4720)
A vulnerability labeled as critical has been found in CloverHackyColor CloverBootloader. The impacted element is an unknown function of the file MdeModulePkg/Universal/RegularExpressionDxe/Oniguruma. The manipulation results in out-of-bounds write.
This vulnerability is cataloged as CVE-2026-24795. The attack must be initiated from a local position. There is no exploit available.
The affected component should be upgraded.