Vulnerability Description
EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/tianocore/edk2/security/advisories/GHSA-xpcr-7hjq-m6qm
- https://lists.debian.org/debian-lts-announce/2025/06/msg00007.html
- https://security.netapp.com/advisory/ntap-20241206-0006/
FAQ
What is CVE-2024-38796?
CVE-2024-38796 is a vulnerability with a CVSS score of 5.9 (MEDIUM). EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lea...
How severe is CVE-2024-38796?
CVE-2024-38796 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38796?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.