EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade edk2-ovmfUpgrade edk2-tools-docUpgrade edk2-aarch64Upgrade edk2-tools | Dec 19, 2024 | Sep 27, 2024 |
| Amazon Linux Ami 2 | — | Upgrade edk2-toolsUpgrade edk2-debuginfoUpgrade edk2-aarch64Upgrade edk2-ovmfUpgrade edk2-tools-doc | Dec 20, 2024 | Sep 27, 2024 |
| Debian | — | Upgrade edk2 | Mar 17, 2025 | Sep 27, 2024 |
| Dell Poweredge Dsa2025038 | — | Upgrade Dell PowerEdge to the latest version | Oct 23, 2025 | Feb 19, 2025 |
| Dell Poweredge Dsa2025256 | — | Upgrade Dell PowerEdge to the latest version | Jan 12, 2026 | Jun 23, 2025 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Dec 15, 2025 |
| Oracle_linux | — | Upgrade edk2-toolsUpgrade edk2-aarch64Upgrade edk2-tools-docUpgrade edk2-ovmf | Dec 18, 2024 | Sep 27, 2024 |
| Redhat_linux | — | Upgrade edk2-aarch64Upgrade edk2-debugsourceUpgrade edk2-tools-docUpgrade edk2-ovmfUpgrade edk2-toolsUpgrade edk2-tools-debuginfo | Nov 27, 2024 | Sep 27, 2024 |
| Rocky_linux | — | Upgrade edk2-tools-debuginfoUpgrade edk2-tools | Feb 9, 2026 | Mar 17, 2025 |
| Ubuntu | — | Upgrade ovmfUpgrade ovmf-ia32Upgrade qemu-efi-aarch64Upgrade qemu-efi-riscv64Upgrade qemu-efi-armUpgrade qemu-efi-loongarch64Upgrade qemu-efi | Nov 27, 2025 | Sep 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub