CVE-2024-38798
published 2025-12-09CVE-2024-38798: EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful…
PriorityP424medium5.8CVSS 4.0
AVLACHATNPRLUINVCHVILVALSCLSILSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.12%
2.5th percentile
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to
possible information disclosure or escalation of privilege
and impact Confidentiality.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | edk2 | < edk2 2025.11-1 (sid) | edk2 2025.11-1 (sid) |
| tianocore | edk2 | < edk2-stable202511 | edk2-stable202511 |
CVSS provenance
nvdv4.05.8MEDIUMCVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-38798: EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access
osv·2025-12-09·CVSS 5.8
CVE-2024-38798 [MEDIUM] CVE-2024-38798: EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.
GHSA
GHSA-r48c-47wj-rhc5: EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access
ghsa_unreviewed·2025-12-09
CVE-2024-38798 [MEDIUM] CWE-200 GHSA-r48c-47wj-rhc5: EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to
possible information disclosure or escalation of privilege
and impact Confidentiality.
Red Hat
EDK2: EDK2: Information Disclosure and Privilege Escalation via Local BIOS Access
vendor_redhat·2025-12-09·CVSS 5.8
CVE-2024-38798 [MEDIUM] CWE-200 EDK2: EDK2: Information Disclosure and Privilege Escalation via Local BIOS Access
EDK2: EDK2: Information Disclosure and Privilege Escalation via Local BIOS Access
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to
possible information disclosure or escalation of privilege
and impact Confidentiality.
A flaw was found in EDK2. This vulnerability allows information disclosure or escalation of privilege via local access to the BIOS (Basic Input/Output System).
Statement: This vulnerability is rated Moderate for Red Hat as it requires local access to the system. The flaw in EDK2, a BIOS component, could lead to information disclosure or escalation of privilege by an attacker with local access. This primarily affects the u
Debian
CVE-2024-38798: edk2 - EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of S...
vendor_debian·2024·CVSS 5.8
CVE-2024-38798 [MEDIUM] CVE-2024-38798: edk2 - EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of S...
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 2025.11-1)
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2024-38798 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2024-38798 [MEDIUM] CVE-2024-38798 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-38798 :
Linux Debian vulnerability analysis and mitigation
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to
possible information disclosure or escalation of privilege
and impact Confidentiality.
Source : NVD
## 5.8
Score
Published December 9, 2025
Severity MEDIUM
CNA Score 5.8
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
edk2-debuginfo
edk2-ovmf
Sources
NVD
Debian 11, 14 No Fix Added at: Dec
Bugzilla
CVE-2024-38798 edk2: EDK2: Information Disclosure and Privilege Escalation via Local BIOS Access [fedora-42]
bugzilla·2025-12-17·CVSS 5.8
CVE-2024-38798 [MEDIUM] CVE-2024-38798 edk2: EDK2: Information Disclosure and Privilege Escalation via Local BIOS Access [fedora-42]
CVE-2024-38798 edk2: EDK2: Information Disclosure and Privilege Escalation via Local BIOS Access [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's pol
2025-12-09
Published