CVE-2024-36350
ubuntu amd64-microcode: Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
mediumEPSS 0.5%
Affected
- ubuntu/amd64-microcode
3.20251202.1ubuntu0.24.04.1..* - ubuntu/amd64-microcode
3.20251202.1ubuntu0.25.10.1..*
Description
A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
Affected operating systems
linux
ubuntu / amd64-microcodenoble
linux
ubuntu / amd64-microcodequesting
Metrics
Show all metrics
Severity
medium
51.21
no public PoC known
5.6
Published
2025-07-08 16:56 UTC
CWE-1421
Weakness classes (CWE)
CWE-1421Base
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
A processor event may allow transient operations to access architecturally restricted data (for example, in another address space) in a shared microarchitectural structure (for example, a CPU cache), potentially exposing the data over a covert channel.
cwe.mitre.org →
References & sources
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7029.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- http://xenbits.xen.org/xsa/advisory-471.html
- http://www.openwall.com/lists/oss-security/2025/08/28/2