ALINUX4-SA-2026:0310
摘要
Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2025-2296: EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability. **Solution**: 请您尽快将升级到修复后的版本。修复命令如下: yum update --advisory ALINUX4-SA-2026:0310 **Affected Products**: Alinux 4
正文
Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2025-2296: EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
标签
- cve:cve-2025-2296
- severity:important
- type:advisory
- vendor:alibaba
扩展字段
{
"advisory_id": "ALINUX4-SA-2026:0310",
"affected_products": [
"Alinux 4"
],
"cve_ids": [
"CVE-2025-2296"
],
"raw_pub_date": "Thu, 23 Jul 2026 16:07:24 +0800",
"solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0310"
}