CVE-2024-36350

ubuntu amd64-microcode: Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution

mediumEPSS 0.5%

Affected

  • ubuntu/amd64-microcode 3.20251202.1ubuntu0.24.04.1..*
  • ubuntu/amd64-microcode 3.20251202.1ubuntu0.25.10.1..*

Description

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.

Affected operating systems

  • linux

    ubuntu / amd64-microcodenoble

  • linux

    ubuntu / amd64-microcodequesting

Metrics

5.6
Source: cna-v3
40.5 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
medium
no public PoC known
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-07-08 16:56 UTC
CWE-1421

Weakness classes (CWE)

  • CWE-1421Base

    Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution

    A processor event may allow transient operations to access architecturally restricted data (for example, in another address space) in a shared microarchitectural structure (for example, a CPU cache), potentially exposing the data over a covert channel.

    cwe.mitre.org →

References & sources

Linked advisories