CVE-2024-38796

EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
ADJACENT_NETWORK
HIGH
LOW
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
TianoCoreCNA
5.9 MEDIUM
ADJACENT_NETWORK
HIGH
LOW
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
CISA-ADPADP
---
---
CVEADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Debian logo
Debian Releases
Debian Product
Codename
edk2
bullseye
vulnerable
bullseye (security)
2020.11-2+deb11u3
fixed
bookworm
2022.11-6+deb12u2
fixed
bookworm (security)
vulnerable
trixie
2025.02-8
fixed
forky
2025.02-9
fixed
sid
2025.08.01-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
edk2
questing
not-affected
plucky
not-affected
oracular
ignored
noble
Fixed 2024.02-2ubuntu0.6
released
jammy
Fixed 2022.02-3ubuntu0.22.04.4
released
focal
needs-triage
bionic
needs-triage
xenial
needs-triage