EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 8 | RedHat | edk2-0:20220126gitbb1bba3d77-13.el8_10.4 | * |
Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | edk2-0:20190829git37eef91017ad-9.el8_2.6 | * |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | edk2-0:20200602gitca407c7246bf-4.el8_4.7 | * |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | RedHat | edk2-0:20200602gitca407c7246bf-4.el8_4.7 | * |
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | RedHat | edk2-0:20200602gitca407c7246bf-4.el8_4.7 | * |
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | edk2-0:20220126gitbb1bba3d77-2.el8_6.7 | * |
Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | edk2-0:20220126gitbb1bba3d77-2.el8_6.7 | * |
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | edk2-0:20220126gitbb1bba3d77-2.el8_6.7 | * |
Red Hat Enterprise Linux 8.8 Extended Update Support | RedHat | edk2-0:20220126gitbb1bba3d77-4.el8_8.7 | * |
Red Hat Enterprise Linux 9 | RedHat | edk2-0:20240524-6.el9_5.3 | * |
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | edk2-0:20220126gitbb1bba3d77-3.el9_0.6 | * |
Red Hat Enterprise Linux 9.2 Extended Update Support | RedHat | edk2-0:20221207gitfff6d81270b5-9.el9_2.5 | * |
Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | edk2-0:20231122-6.el9_4.6 | * |