Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-1298

Опубликовано: 30 мая 2024
Источник: debian

Описание

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
edk2fixed2024.05-1package
edk2fixed2022.11-6+deb12u2bookwormpackage

Примечания

  • https://github.com/tianocore/edk2/security/advisories/GHSA-chfw-xj8f-6m53

  • https://bugzilla.tianocore.org/show_bug.cgi?id=4677

  • https://github.com/tianocore/edk2/pull/5659

  • Fixed by: https://github.com/tianocore/edk2/commit/284dbac43da752ee34825c8b3f6f9e8281cb5a19 (edk2-stable202405)

Связанные уязвимости

CVSS3: 6
ubuntu
около 1 года назад

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
redhat
около 1 года назад

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
nvd
около 1 года назад

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
msrc
около 1 года назад

Описание отсутствует

suse-cvrf
7 месяцев назад

Security update for ovmf