CVE-2024-36350
Advisory lineage Upstream: 0 Downstream: 54
Deferred
Published: 08 Jul 2025, 16:56
Last modified:04 Nov 2025, 21:08
Vulnerability Summary
Overall Risk (default)
low
22/100 CVSS Score
5.6 MEDIUM
v3.1 (cve.org)
EPSS Score
0.03% LOW
0% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
08 Jul 2025, 16:56
Published
Vulnerability first disclosed
04 Nov 2025, 21:08
Last Modified
Vulnerability information updated
Description
A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.03%• Percentile: 10%
Techniques & Countermeasures
- CWE-1421•Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
A processor event may allow transient operations to access architecturally restricted data (for example, in another address space) in a shared microarchitectural structure (for example, a CPU cache), potentially exposing the data over a covert channel.
References (5)
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7029.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- http://xenbits.xen.org/xsa/advisory-471.html
- http://www.openwall.com/lists/oss-security/2025/08/28/2