Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66122.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-66122
Upstream
Published
2025-08-07T01:15:25Z
Modified
2026-04-01T05:20:42.106620Z
Summary
CVE-2025-3770 affecting package hvloader for versions less than 1.0.1-14
Details

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.

References

Affected packages

Azure Linux:2 / hvloader

Package

Name
hvloader
Purl
pkg:rpm/azure-linux/hvloader

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1-14

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66122.json"