CVE-2024-36357

ubuntu amd64-microcode: Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution

mediumEPSS 0.4%

Affected

  • ubuntu/amd64-microcode 3.20251202.1ubuntu0.24.04.1..*
  • ubuntu/amd64-microcode 3.20251202.1ubuntu0.25.10.1..*

Description

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.

Affected operating systems

  • linux

    ubuntu / amd64-microcodenoble

  • linux

    ubuntu / amd64-microcodequesting

Metrics

5.6
Source: cna-v3
27.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-07-08 17:01 UTC
CWE-1421

Weakness classes (CWE)

  • CWE-1421Base

    Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution

    A processor event may allow transient operations to access architecturally restricted data (for example, in another address space) in a shared microarchitectural structure (for example, a CPU cache), potentially exposing the data over a covert channel.

    cwe.mitre.org →

References & sources

Linked advisories