CVE-2024-36357
ubuntu amd64-microcode: Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
mediumEPSS 0.4%
Affected
- ubuntu/amd64-microcode
3.20251202.1ubuntu0.24.04.1..* - ubuntu/amd64-microcode
3.20251202.1ubuntu0.25.10.1..*
Description
A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
Affected operating systems
linux
ubuntu / amd64-microcodenoble
linux
ubuntu / amd64-microcodequesting
Metrics
Show all metrics
Severity
medium
44.11
no public PoC known
5.6
Published
2025-07-08 17:01 UTC
CWE-1421
Weakness classes (CWE)
CWE-1421Base
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
A processor event may allow transient operations to access architecturally restricted data (for example, in another address space) in a shared microarchitectural structure (for example, a CPU cache), potentially exposing the data over a covert channel.
cwe.mitre.org →
References & sources
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7029.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- http://xenbits.xen.org/xsa/advisory-471.html
- http://www.openwall.com/lists/oss-security/2025/08/28/2