Bugzilla – Bug 1225889
VUL-0: CVE-2024-1298: ovmf: edk2: Temporary DoS vulnerability
Last modified: 2024-07-02 13:48:24 UTC
EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-1298 https://www.cve.org/CVERecord?id=CVE-2024-1298 https://github.com/tianocore/edk2/security/advisories/GHSA-chfw-xj8f-6m53 https://bugzilla.redhat.com/show_bug.cgi?id=2284243