Skip to content
IntelCVE-2026-28729

Intel Slim Bootloader may allow an information disclosure. S: integer overflow

Low2.4CVE-2026-28729 · Published Aug 11, 2026 · updated Aug 12, 2026

Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (none) and availability (low) impacts.

Intel advisory

Affected versions

PackageAffectedFixed in
Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combi
Product
<= See referencesNo fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-190

More Intel advisories

All Intel
Advisory
Intel reference platforms: information disclosure
Medium4.0Aug 11
Intel Xeon processors: improper input validation
Medium4.0Aug 11
Intel Processors: information disclosure
Medium4.0Aug 11
Intel Extension for PyTorch: unsafe deserialization
Medium4.6Aug 11
Intel Transfer Learning Tool: privilege escalation
Medium6.3Aug 11
Intel Workload Services Framework software: privilege escalation
Medium5.4Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.