VDB
BDU%3A2024-01537
BDU%3A2024-01537
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость функции tcg2measurepeimage() библиотеки Tianocore EDK2 , вызванная переполнением буфера, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, Canonical Ltd., ООО «Ред Софт», ООО «РусБИТех-Астра», Tianocore | Red Hat Enterprise Linux, Debian GNU/Linux, Ubuntu, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), edk2 |
Timeline
- Feb 25, 2024 CVE Published
- Nov 11, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- https://github.com/tianocore/edk2/security/advisories/GHSA-4hcq-p8q8-hj8j url
- https://github.com/tianocore/edk2/pull/5264 url
- https://bugzilla.tianocore.org/show_bug.cgi?id=4118 url
- https://security-tracker.debian.org/tracker/CVE-2022-36764 url
- https://access.redhat.com/security/cve/CVE-2022-36764 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2024-1031SE47 url
- https://ubuntu.com/security/notices/USN-6638-1 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2024-0830SE17 advisory