Lucene search

K
amazonAmazonALAS-2024-2578
HistoryJun 19, 2024 - 7:15 p.m.

Medium: edk2

2024-06-1919:15:00
alas.aws.amazon.com
9
edk2
s3 sleep
vulnerability
unit32 overflow
availability
update
amazon linux 2
cve-2024-1298
red hat
mitre

CVSS3

6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

AI Score

6.9

Confidence

Low

Issue Overview:

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability. (CVE-2024-1298)

Affected Packages:

edk2

Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.

Issue Correction:
Run yum update edk2 to update your system.

New Packages:

aarch64:  
    edk2-tools-20200801stable-1.amzn2.0.7.aarch64  
    edk2-debuginfo-20200801stable-1.amzn2.0.7.aarch64  
  
noarch:  
    edk2-tools-python-20200801stable-1.amzn2.0.7.noarch  
    edk2-tools-doc-20200801stable-1.amzn2.0.7.noarch  
    edk2-ovmf-20200801stable-1.amzn2.0.7.noarch  
    edk2-aarch64-20200801stable-1.amzn2.0.7.noarch  
  
src:  
    edk2-20200801stable-1.amzn2.0.7.src  
  
x86_64:  
    edk2-tools-20200801stable-1.amzn2.0.7.x86_64  
    edk2-debuginfo-20200801stable-1.amzn2.0.7.x86_64  

Additional References

Red Hat: CVE-2024-1298

Mitre: CVE-2024-1298

CVSS3

6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

AI Score

6.9

Confidence

Low