Advisories ยป MGASA-2025-0124

Updated microcode packages fix security vulnerability

Publication date: 03 Apr 2025
Modification date: 03 Apr 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-56161

Description

Improper signature verification in AMD CPU ROM microcode patch loader
may allow an attacker with local administrator privilege to load
malicious CPU microcode resulting in loss of confidentiality and
integrity of a confidential guest running under AMD SEV-SNP.
(CVE-2024-56161)
                

References

SRPMS

9/nonfree