INFBA-2025:15878: linux-firmware security update
Information about definition
Identificator: INFBA-2025:15878
Type: bugfix
Release date: 2025-10-31 13:42:00 UTC
Information about package
The linux-firmware packages contain all of the firmware files that are required by various devices to operate.
Vulnerabilities description
- CVE-2024-36357
A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
Severity level
| CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
|---|---|---|---|
|
NIST — CVE-2024-36357
|
no information | 5.6 | no information |
Updated packages