Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-1298

Published: June 3, 2024Last modified: June 4, 2025

Description

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

Severity score breakdown

ParameterValue
Base score6
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredHIGH
User interactionNONE
ScopeCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Notes

The bug is present in 202405 and earlier. The bug is fixed in edk2-stable202405 We still have 202308. Debian points to the commit with the fix: https://github.com/tianocore/edk2/commit/284dbac43da752ee34825c8b3f6f9e8281cb5a19

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSedk2Vulnerable (0.0.202208-r0)
Streamedk2Vulnerable (0.0.202302-r0)

References

ON THIS PAGE