Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54393 | EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability. |
Ubuntu USN |
USN-7894-1 | EDK II vulnerabilities |
Tue, 08 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 07 Apr 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability. | |
| Title | Out-of-bounds Read in HashPeImageByType() | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TianoCore
Published:
Updated: 2025-04-08T16:00:53.582Z
Reserved: 2024-06-19T17:05:09.904Z
Link: CVE-2024-38797
Updated: 2025-04-08T14:20:29.630Z
Status : Deferred
Published: 2025-04-07T18:15:45.337
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-38797
OpenCVE Enrichment
Updated: 2025-07-13T11:14:53Z
EUVD
Ubuntu USN