Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:02516-1

Опубликовано: 24 июл. 2025
Источник: suse-cvrf

Описание

Security update for ovmf

This update for ovmf fixes the following issues:

  • CVE-2024-1298: Fixed potential UINT32 overflow in S3 ResumeCount (bsc#1225889).

Other fixes:

  • Fixed Kubevirt GPU passthrough failure (bsc#1245542)

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP6
qemu-ovmf-x86_64-202308-150600.5.19.1
qemu-ovmf-x86_64-debug-202308-150600.5.19.1
qemu-uefi-aarch32-202308-150600.5.19.1
qemu-uefi-aarch64-202308-150600.5.19.1
SUSE Linux Enterprise Module for Server Applications 15 SP6
ovmf-202308-150600.5.19.1
ovmf-tools-202308-150600.5.19.1
qemu-ovmf-x86_64-202308-150600.5.19.1
qemu-uefi-aarch64-202308-150600.5.19.1
openSUSE Leap 15.6
ovmf-202308-150600.5.19.1
ovmf-tools-202308-150600.5.19.1
qemu-ovmf-ia32-202308-150600.5.19.1
qemu-ovmf-x86_64-202308-150600.5.19.1
qemu-ovmf-x86_64-debug-202308-150600.5.19.1
qemu-uefi-aarch32-202308-150600.5.19.1
qemu-uefi-aarch64-202308-150600.5.19.1

Описание

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:qemu-ovmf-x86_64-202308-150600.5.19.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:qemu-ovmf-x86_64-debug-202308-150600.5.19.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:qemu-uefi-aarch32-202308-150600.5.19.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:qemu-uefi-aarch64-202308-150600.5.19.1

Ссылки
Уязвимость SUSE-SU-2025:02516-1