CVE-2024-36349

Eine vorübergehende Ausführungsschwachstelle in einigen AMD-Prozessoren kann es einem Benutzerprozess ermöglichen, TSC_AUX abzuleiten, au…

Description

A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage.

Metrics

3.8
Source: cna-v3
8.2 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
low
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-07-08 16:42 UTC
CWE-1420

Weakness classes (CWE)

  • CWE-1420Base

    Exposure of Sensitive Information during Transient Execution

    A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.

    cwe.mitre.org →

References & sources

Linked advisories