Your message dated Thu, 24 Oct 2024 18:20:24 +0000
with message-id <[email protected]>
and subject line Bug#1084055: fixed in edk2 2024.08-3
has caused the Debian Bug report #1084055,
regarding edk2: CVE-2024-38796
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1084055: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1084055
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: edk2
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for edk2.

CVE-2024-38796[0]:
| EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An
| Attacker may cause memory corruption due to an overflow via an
| adjacent network. A successful exploit of this vulnerability may
| lead to a loss of Confidentiality, Integrity, and/or Availability.

https://github.com/tianocore/edk2/security/advisories/GHSA-xpcr-7hjq-m6qm
https://bugzilla.tianocore.org/show_bug.cgi?id=1993
https://github.com/tianocore/edk2/pull/6249


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-38796
    https://www.cve.org/CVERecord?id=CVE-2024-38796

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: edk2
Source-Version: 2024.08-3
Done: dann frazier <[email protected]>

We believe that the bug you reported is fixed in the latest version of
edk2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
dann frazier <[email protected]> (supplier of updated edk2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 24 Oct 2024 11:11:27 -0600
Source: edk2
Architecture: source
Version: 2024.08-3
Distribution: unstable
Urgency: medium
Maintainer: Debian QEMU Team <[email protected]>
Changed-By: dann frazier <[email protected]>
Closes: 1084055
Changes:
 edk2 (2024.08-3) unstable; urgency=medium
 .
   * Fix overflow condition in PeCoffLoaderRelocateImage(), CVE-2024-38796:
     - d/p/0001-MdePkg-Fix-overflow-issue-in-BasePeCoffLib.patch
     - d/p/0002-MdePkg-Improving-readability-of-CVE-patch-for-PeCoff.patch
     (Closes: #1084055)
   * OpenSSL: Avoid type errors in EAI-related name check logic, CVE-2024-6119:
     - d/p/0001-Avoid-type-errors-in-EAI-related-name-check-logic.patch
Checksums-Sha1:
 9d5da25ed3ca5d00f2af1fbb8bf95f6bdec8205e 2427 edk2_2024.08-3.dsc
 68cf8c6a097a7bcb52f86a48d11d14b1dcdf81ac 49372 edk2_2024.08-3.debian.tar.xz
 7a68aa6e5189756f302a8f98c5f28b6d075b3ec3 11320 edk2_2024.08-3_source.buildinfo
Checksums-Sha256:
 a5d083d1b313b9e371154bfaacf63e776f4fa76c6c366a8359c2037138903b7b 2427 
edk2_2024.08-3.dsc
 16e0a831c6b2e180d4b862e22ebebfab6c4bcc6f7f46e3712daf8808538d2ec1 49372 
edk2_2024.08-3.debian.tar.xz
 3c7f9cb332c537ccf3a5bca2313aacbccb668be3c9bed8e40fa3a5e2b69c3e4c 11320 
edk2_2024.08-3_source.buildinfo
Files:
 f0d2f559c77262d567d847aff20d6d6b 2427 misc optional edk2_2024.08-3.dsc
 b4ba5424d9e972acff583880acd14d4e 49372 misc optional 
edk2_2024.08-3.debian.tar.xz
 ec424c1e8c0e39b94bad02f1b5245cf9 11320 misc optional 
edk2_2024.08-3_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iIcEARYKAC8WIQTAII4uHC7E3OGrB54TEoKfKLdfNAUCZxqAkxEcZGFubmZAZGVi
aWFuLm9yZwAKCRATEoKfKLdfNBEiAP432p4zEYSrGEt32L3qJEh8V8kfQQYNeo56
VEPc3s5K4gD+MUE5sg+I/jih1rLb85O03EMuAgctKVHAwpcYIZTQkwQ=
=H3Us
-----END PGP SIGNATURE-----

Attachment: pgpJWJriOvtjW.pgp
Description: PGP signature


--- End Message ---

Reply via email to