UbuntuUpdates.org

Bugs fixes in "edk2"

Origin Bug number Title Date fixed
CVE CVE-2024-38797 EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via 2025-11-27
CVE CVE-2024-13176 Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summ 2025-11-27
CVE CVE-2025-9232 Out-of-bounds read in HTTP client no_proxy handling 2025-11-27
CVE CVE-2025-3770 EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vul 2025-11-27
CVE CVE-2025-2295 EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vu 2025-11-27
CVE CVE-2024-38805 EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vu 2025-11-27
CVE CVE-2024-38797 EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via 2025-11-27
CVE CVE-2024-13176 Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summ 2025-11-27
CVE CVE-2025-9232 Out-of-bounds read in HTTP client no_proxy handling 2025-11-27
CVE CVE-2025-3770 EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vul 2025-11-27
CVE CVE-2025-2295 EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vu 2025-11-27
CVE CVE-2024-38805 EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vu 2025-11-27
CVE CVE-2024-38797 EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via 2025-11-27
CVE CVE-2024-13176 Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summ 2025-11-27
Launchpad 2122286 firmware definitions lack \ 2025-11-19
Launchpad 2122286 firmware definitions lack \ 2025-11-19
Launchpad 2122286 firmware definitions lack \ 2025-10-23
Launchpad 2122286 firmware definitions lack \ 2025-10-23
Launchpad 2106771 Add support for QEMU AMD SNP VM Measured linux boot with the addition of new AMDSEV OVMF.fd 2025-08-21
Launchpad 2106771 Add support for QEMU AMD SNP VM Measured linux boot with the addition of new AMDSEV OVMF.fd 2025-08-20



About   -   Send Feedback to @ubuntu_updates