DSA-2025-140: Security Update for Dell Precision Rack BIOS for a Tianocore EDK2 Vulnerability
Summary: Dell Precision Rack BIOS remediation is available for a Tianocore EDK2 vulnerability that could be exploited by malicious users to compromise the affected system.
Impact
Medium
Details
|
Third-Party Component |
CVEs |
More information |
|
Tianocore EDK2 |
CVE-2024-38796 |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Precision 7920 Rack |
BIOS |
Versions prior to 2.23.0 |
Version 2.23.0 or later |
02/18/2025 |
|
|
Precision 7920 XL Rack |
BIOS |
Versions prior to 2.23.0 |
Version 2.23.0 or later |
02/18/2025 |
|
|
Precision 7960 Rack |
BIOS |
Versions prior to 2.5.4 |
Version 2.5.4 or later |
03/28/2025 |
|
|
Precision 7960 XL Rack |
BIOS |
Versions prior to 2.5.4 |
Version 2.5.4 or later |
03/28/2025 |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Precision 7920 Rack |
BIOS |
Versions prior to 2.23.0 |
Version 2.23.0 or later |
02/18/2025 |
|
|
Precision 7920 XL Rack |
BIOS |
Versions prior to 2.23.0 |
Version 2.23.0 or later |
02/18/2025 |
|
|
Precision 7960 Rack |
BIOS |
Versions prior to 2.5.4 |
Version 2.5.4 or later |
03/28/2025 |
|
|
Precision 7960 XL Rack |
BIOS |
Versions prior to 2.5.4 |
Version 2.5.4 or later |
03/28/2025 |
Workarounds & Mitigations
None
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-03-25 |
Initial Release |
|
2.0 |
2025-04-09 |
Updated Affected Products and Remediation section: Final Platform list updated. Added Precision 7960 Rack |