CVE-2024-38797 Information

Description

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.

Reference

https://github.com/tianocore/edk2/security/advisories/GHSA-4wjw-6xmf-44xf

Share on: