Wind River Support Network

HomeDefectsLIN1024-8438
Fixed

LIN1024-8438 : Security Advisory - ovmf - CVE-2024-38797

Created: Apr 7, 2025    Updated: Jul 10, 2025
Resolved Date: Jul 10, 2025
Found In Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.

CREATE(Triage):(User=admin) CVE-2024-38797 (https://nvd.nist.gov/vuln/detail/CVE-2024-38797)

CVEs


Live chat
Online