cbcvebase.

Debian Edk2 vulnerabilities

47 known vulnerabilities affecting debian/edk2.

Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH18MEDIUM19LOW9

Vulnerabilities

Page 2 of 3
CVE-2018-12179P3LOWCVSS 7.8fixed in edk2 0~20190606.20d2e5a1-2 (bookworm)2018
CVE-2018-12179 [HIGH] CVE-2018-12179: edk2 - Improper configuration in system firmware for EDK II may allow unauthenticated u... Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access. Scope: local bookworm: resolved (fixed in 0~20190606.20d2e5a1-2) bullseye: resolved (fixed in 0~20190606.20d2e5a1-2) forky: resolved (fixed in 0~20190606.20d2e5a1-2) sid: res
debian
CVE-2021-28213P3LOWCVSS 7.5fixed in edk2 0~20190606.20d2e5a1-2 (bookworm)2021
CVE-2021-28213 [HIGH] CVE-2021-28213: edk2 - Example EDK2 encrypted private key in the IpSecDxe.efi present potential securit... Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks. Scope: local bookworm: resolved (fixed in 0~20190606.20d2e5a1-2) bullseye: resolved (fixed in 0~20190606.20d2e5a1-2) forky: resolved (fixed in 0~20190606.20d2e5a1-2) sid: resolved (fixed in 0~20190606.20d2e5a1-2) trixie: resolved (fixed in 0~20190606.20d2e5a1-2)
debian
CVE-2019-14563P3LOWCVSS 7.8fixed in edk2 0~20200229.4c0f6e34-1 (bookworm)2019
CVE-2019-14563 [HIGH] CVE-2019-14563: edk2 - Integer truncation in EDK II may allow an authenticated user to potentially enab... Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access. Scope: local bookworm: resolved (fixed in 0~20200229.4c0f6e34-1) bullseye: resolved (fixed in 0~20200229.4c0f6e34-1) forky: resolved (fixed in 0~20200229.4c0f6e34-1) sid: resolved (fixed in 0~20200229.4c0f6e34-1) trixie: resolved (fixed in 0~2020
debian
CVE-2019-14575P3LOWCVSS 7.8fixed in edk2 0~20200229.4c0f6e34-1 (bookworm)2019
CVE-2019-14575 [HIGH] CVE-2019-14575: edk2 - Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticat... Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access. Scope: local bookworm: resolved (fixed in 0~20200229.4c0f6e34-1) bullseye: resolved (fixed in 0~20200229.4c0f6e34-1) forky: resolved (fixed in 0~20200229.4c0f6e34-1) sid: resolved (fixed in 0~20200229.4c0f6e34-1) trixie
debian
CVE-2021-28216P4HIGHCVSS 7.8fixed in edk2 2021.11~rc1-1 (bookworm)2021
CVE-2021-28216 [HIGH] CVE-2021-28216: edk2 - BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend se... BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE. Scope: local bookworm: resolved (fixed in 2021.11~rc1-1) bullseye: resolved (fixed in 2020.11-2+deb11u3) forky: resolved (fixed in 2021.11~rc1-1) sid: resolved (fixed in 2021.11~rc1-1) trixie: resolved (fixed in 2021.11~rc1-1)
debian
CVE-2019-14584P4HIGHCVSS 7.8fixed in edk2 2020.11-1 (bookworm)2019
CVE-2019-14584 [HIGH] CVE-2019-14584: edk2 - Null pointer dereference in Tianocore EDK2 may allow an authenticated user to po... Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access. Scope: local bookworm: resolved (fixed in 2020.11-1) bullseye: resolved (fixed in 2020.11-1) forky: resolved (fixed in 2020.11-1) sid: resolved (fixed in 2020.11-1) trixie: resolved (fixed in 2020.11-1)
debian
CVE-2025-3770P3HIGHCVSS 7.0fixed in edk2 2025.02-9 (forky)2025
CVE-2025-3770 [HIGH] CVE-2025-3770: edk2 - EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Me... EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2025.02-9) sid: resolved (fixed in 2025.02-9) tri
debian
CVE-2023-48733P4MEDIUMCVSS 6.7fixed in edk2 2022.11-6+deb12u1 (bookworm)2023
CVE-2023-48733 [MEDIUM] CVE-2023-48733: edk2 - An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK... An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye: resolved (fixed in 2020.11-2+deb11u2) forky: resolved (fixed in 2023.11-7) sid: resolved (fixed in 2023.11-7) trixie: resolved (fixed in 2023.11-7)
debian
CVE-2023-45229P4MEDIUMCVSS 6.5fixed in edk2 2022.11-6+deb12u1 (bookworm)2023
CVE-2023-45229 [MEDIUM] CVE-2023-45229: edk2 - EDK2's Network Package is susceptible to an out-of-bounds read vulnerability wh... EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye: resolved (fixed in
debian
CVE-2023-45231P4MEDIUMCVSS 6.5fixed in edk2 2022.11-6+deb12u1 (bookworm)2023
CVE-2023-45231 [MEDIUM] CVE-2023-45231: edk2 - EDK2's Network Package is susceptible to an out-of-bounds read vulnerability wh... EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye: resolved (fixed in 2020.11-2+deb11u3)
debian
CVE-2024-38796P4MEDIUMCVSS 5.9fixed in edk2 2022.11-6+deb12u2 (bookworm)2024
CVE-2024-38796 [MEDIUM] CVE-2024-38796: edk2 - EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker ma... EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u2) bullseye: resolved (fixed in 2020.11-2+deb11
debian
CVE-2021-28211P4MEDIUMCVSS 6.7fixed in edk2 2020.11-1 (bookworm)2021
CVE-2021-28211 [MEDIUM] CVE-2021-28211: edk2 - A heap overflow in LzmaUefiDecompressGetInfo function in EDK II. A heap overflow in LzmaUefiDecompressGetInfo function in EDK II. Scope: local bookworm: resolved (fixed in 2020.11-1) bullseye: resolved (fixed in 2020.11-1) forky: resolved (fixed in 2020.11-1) sid: resolved (fixed in 2020.11-1) trixie: resolved (fixed in 2020.11-1)
debian
CVE-2024-38805P4MEDIUMCVSS 6.3fixed in edk2 2025.02-9 (forky)2024
CVE-2024-38805 [MEDIUM] CVE-2024-38805: edk2 - EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow... EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2025.02-9) sid: resolved (fixed in 2025.02-9) trixie: resolved (fixed in 2025.02-8+deb13u1)
debian
CVE-2018-12183P4MEDIUMCVSS 6.8fixed in edk2 0~20181115.85588389-1 (bookworm)2018
CVE-2018-12183 [MEDIUM] CVE-2018-12183: edk2 - Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potent... Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access. Scope: local bookworm: resolved (fixed in 0~20181115.85588389-1) bullseye: resolved (fixed in 0~20181115.85588389-1) forky: resolved (fixed in 0~20181115.85588389-1) sid: resolved (fixe
debian
CVE-2019-11098P4MEDIUMCVSS 6.8fixed in edk2 2020.11-5 (bookworm)2019
CVE-2019-11098 [MEDIUM] CVE-2019-11098: edk2 - Insufficient input validation in MdeModulePkg in EDKII may allow an unauthentica... Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access. Scope: local bookworm: resolved (fixed in 2020.11-5) bullseye: resolved (fixed in 2020.11-2+deb11u1) forky: resolved (fixed in 2020.11-5) sid: resolved (fixed in 20
debian
CVE-2024-38798P4MEDIUMCVSS 5.8fixed in edk2 2025.11-1 (sid)2024
CVE-2024-38798 [MEDIUM] CVE-2024-38798: edk2 - EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of S... EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality. Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in
debian
CVE-2019-14553P4LOWCVSS 4.9fixed in edk2 0~20190828.37eef910-4 (bookworm)2019
CVE-2019-14553 [MEDIUM] CVE-2019-14553: edk2 - Improper authentication in EDK II may allow a privileged user to potentially ena... Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access. Scope: local bookworm: resolved (fixed in 0~20190828.37eef910-4) bullseye: resolved (fixed in 0~20190828.37eef910-4) forky: resolved (fixed in 0~20190828.37eef910-4) sid: resolved (fixed in 0~20190828.37eef910-4) trixie: resolved (fixed in 0~
debian
CVE-2019-14587P4MEDIUMCVSS 6.5fixed in edk2 0~20200229.4c0f6e34-1 (bookworm)2019
CVE-2019-14587 [MEDIUM] CVE-2019-14587: edk2 - Logic issue EDK II may allow an unauthenticated user to potentially enable denia... Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access. Scope: local bookworm: resolved (fixed in 0~20200229.4c0f6e34-1) bullseye: resolved (fixed in 0~20200229.4c0f6e34-1) forky: resolved (fixed in 0~20200229.4c0f6e34-1) sid: resolved (fixed in 0~20200229.4c0f6e34-1) trixie: resolved (fixed in 0~20200229.4c0f
debian
CVE-2018-12181P4MEDIUMCVSS 6.0fixed in edk2 0~20181115.85588389-3 (bookworm)2018
CVE-2018-12181 [MEDIUM] CVE-2018-12181: edk2 - Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potent... Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access. Scope: local bookworm: resolved (fixed in 0~20181115.85588389-3) bullseye: resolved (fixed in 0~20181115.85588389-3) forky: resolved (fixed in 0~20181115.85588389-3) sid: resolved (fixed in 0~20181115.85588389-3) t
debian
CVE-2019-14558P4MEDIUMCVSS 5.7fixed in edk2 0~20200229.4c0f6e34-1 (bookworm)2019
CVE-2019-14558 [MEDIUM] CVE-2019-14558: edk2 - Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generat... Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable denial of service via adjacent access. Scope: local bookworm: resolved (fixed in 0~20200229.4c0f6e34-1) bullseye: resolved (fixed in 0~20200229.4c0f6e34
debian
Debian Edk2 vulnerabilities | cvebase