CVE Vulnerabilities

CVE-2024-1298

Divide By Zero

Published: May 30, 2024 | Modified: Jun 11, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6 MODERATE
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Ubuntu
MEDIUM

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

Weakness

The product divides a value by zero.

Affected Software

Name Vendor Start Version End Version
Edk2 Ubuntu mantic *
Red Hat Enterprise Linux 8 RedHat edk2-0:20220126gitbb1bba3d77-13.el8_10.2 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat edk2-0:20220126gitbb1bba3d77-2.el8_6.5 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat edk2-0:20220126gitbb1bba3d77-2.el8_6.5 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat edk2-0:20220126gitbb1bba3d77-2.el8_6.5 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat edk2-0:20220126gitbb1bba3d77-4.el8_8.4 *
Red Hat Enterprise Linux 9 RedHat edk2-0:20240524-6.el9_5 *

References