CVE-2024-36348

A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.8 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
AMDCNA
3.8 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Debian logo
Debian Releases
Debian Product
Codename
amd64-microcode
bullseye/non-free
unimportant
bullseye/non-free (security)
unimportant
bookworm/non-free-firmware
unimportant
bookworm/non-free-firmware (security)
unimportant
sid/non-free-firmware
unimportant
forky/non-free-firmware
unimportant
trixie/non-free-firmware
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
amd64-microcode
plucky
deferred
oracular
ignored
noble
deferred
jammy
deferred
focal
deferred
bionic
deferred
xenial
deferred
trusty
deferred