Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Mageia 9: MGASA-2025-0124 critical: AMD CPU microcode integrity issue

mageia
Calendar Grey April 3, 2025
Scroller Mageia
An exploit linked to AMD processor firmware could enable harmful code execution, posing risks to both data privacy and system reliability.
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of ...

Summary

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. (CVE-2024-56161)

References

- https://bugs.mageia.org/show_bug.cgi?id=34149

- https://lists.debian.org/debian-lts-announce/2025/03/msg00024.html

- https://www.cve.org/CVERecord?id=CVE-2024-56161

Resolution

SRPMS

- 9/nonfree/microcode-0.20250211-2.mga9.nonfree

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 03 Apr 2025
URL: https://advisories.mageia.org/MGASA-2025-0124.html
Type: security
CVE: CVE-2024-56161

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.