Debian Edk2 vulnerabilities
47 known vulnerabilities affecting debian/edk2.
Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH18MEDIUM19LOW9
Vulnerabilities
Page 3 of 3
CVE-2019-0161P4LOWCVSS 5.5fixed in edk2 0~20180803.dd4cae4d-1 (bookworm)2019
CVE-2019-0161 [MEDIUM] CVE-2019-0161: edk2 - Stack overflow in XHCI for EDK II may allow an unauthenticated user to potential...
Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 0~20180803.dd4cae4d-1)
bullseye: resolved (fixed in 0~20180803.dd4cae4d-1)
forky: resolved (fixed in 0~20180803.dd4cae4d-1)
sid: resolved (fixed in 0~20180803.dd4cae4d-1)
trixie: resolved (fixed in 0~201
debian
CVE-2024-1298P4MEDIUMCVSS 6.0fixed in edk2 2022.11-6+deb12u2 (bookworm)2024
CVE-2024-1298 [MEDIUM] CVE-2024-1298: edk2 - EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may c...
EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.
Scope: local
bookworm: resolved (fixed in 2022.11-6+deb12u2)
bullseye: resolved (fixed in 2020.11-2+deb11u3)
forky: resolved (fixed in 2024.05-1)
debian
CVE-2024-38797P4MEDIUMCVSS 4.6fixed in edk2 2025.02-8 (forky)2024
CVE-2024-38797 [MEDIUM] CVE-2024-38797: edk2 - EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a rea...
EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2025.02-8)
sid: resolved (fixed i
debian
CVE-2024-13176P4MEDIUMCVSS 4.1fixed in edk2 2025.02-9 (forky)2024
CVE-2024-13176 [MEDIUM] CVE-2024-13176: edk2 - Issue summary: A timing side-channel which could potentially allow recovering th...
Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast n
debian
CVE-2019-14562P4MEDIUMCVSS 5.5fixed in edk2 2020.05-4 (bookworm)2019
CVE-2019-14562 [MEDIUM] CVE-2019-14562: edk2 - Integer overflow in DxeImageVerificationHandler() EDK II may allow an authentica...
Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 2020.05-4)
bullseye: resolved (fixed in 2020.05-4)
forky: resolved (fixed in 2020.05-4)
sid: resolved (fixed in 2020.05-4)
trixie: resolved (fixed in 2020.05-4)
debian
CVE-2025-2295P4LOWCVSS 3.5fixed in edk2 2025.02-4 (forky)2025
CVE-2025-2295 [LOW] CVE-2025-2295: edk2 - EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow...
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2025.02-4)
sid: resolved (fixed in 2025.02-4)
trixie: resolved (fixed in 2025.02-4)
debian
CVE-2021-28210HIGHCVSS 7.8fixed in edk2 2020.11-1 (bookworm)2021
CVE-2021-28210 [HIGH] CVE-2021-28210: edk2 - An unlimited recursion in DxeCore in EDK II.
An unlimited recursion in DxeCore in EDK II.
Scope: local
bookworm: resolved (fixed in 2020.11-1)
bullseye: resolved (fixed in 2020.11-1)
forky: resolved (fixed in 2020.11-1)
sid: resolved (fixed in 2020.11-1)
trixie: resolved (fixed in 2020.11-1)
debian
← Previous3 / 3