Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 9: MGASA-2025-0124 critical: AMD CPU microcode integrity issue

mageia
Calendar Grey April 3, 2025
Dist Mageia Esm H88
An exploit linked to AMD processor firmware could enable harmful code execution, posing risks to both data privacy and system reliability.
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of ...

Summary

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. (CVE-2024-56161)

References

- https://bugs.mageia.org/show_bug.cgi?id=34149

- https://lists.debian.org/debian-lts-announce/2025/03/msg00024.html

- https://www.cve.org/CVERecord?id=CVE-2024-56161

Resolution

SRPMS

- 9/nonfree/microcode-0.20250211-2.mga9.nonfree

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 03 Apr 2025
URL: https://advisories.mageia.org/MGASA-2025-0124.html
Type: security
CVE: CVE-2024-56161

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here