GPU VulnDB

Database/Firmware, BMC & network fabric

EDK2: BIOS exposes sensitive information to a local unauthorized actor

CVSS 5.8CVE-2024-38798Firmware, BMC & network fabriccurated

Impact

A local user on the machine can read data the firmware should keep to itself, and the advisory states the outcome may extend to privilege escalation. EDK2 is the upstream most server BIOS images are built from, so the exposure follows whatever your platform vendor shipped rather than one product. On a GPU node the concern is firmware-held material - keys, measurements, configuration - that underpins secure boot and attestation: if it leaks, the attestation a tenant relies on no longer proves what it claims. The record gives high attack complexity and requires local low-privileged access, so this is a slow escalation path, not a remote break-in. The description is thin on the specific code path; treat the mechanism as unestablished.

Who can reach it

Local user on the host with low privileges. No remote or network path, and no tenant-facing path unless a workload already has host-level code execution.

What to do

There is no EDK2 fix you deploy directly - wait for the BIOS release from your server vendor that picks up the EDK2 fix, then flash each affected node. That means scheduling the node out of service: drain workloads, flash, reboot, re-attest. Plan it as part of a routine firmware campaign rather than an emergency window, given the local-only, high-complexity attack path. The record names no fixed EDK2 tag.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.