Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-36357

Опубликовано: 08 июл. 2025
Источник: debian
EPSS Низкий

Описание

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
amd64-microcodeunfixedpackage
linuxfixed6.12.37-1package
xenunfixedpackage
xenend-of-lifebullseyepackage

Примечания

  • https://xenbits.xen.org/xsa/advisory-471.html

  • https://www.amd.com/content/dam/amd/en/documents/resources/bulletin/technical-guidance-for-mitigating-transient-scheduler-attacks.pdf

  • https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7029.html

  • https://aka.ms/enter-exit-leak

  • https://www.microsoft.com/en-us/research/wp-content/uploads/2025/07/Enter-Exit-SP26.pdf

  • https://gitlab.com/kernel-firmware/linux-firmware/-/commit/331eac9144402d6cfa02ff3b2888a40bb9a7a01a

  • https://gitlab.com/kernel-firmware/linux-firmware/-/commit/3768c184de68a85b9df6697e7f93a2f61de90a99

EPSS

Процентиль: 4%
0.00021
Низкий

Связанные уязвимости

CVSS3: 5.6
ubuntu
2 месяца назад

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.

CVSS3: 5.6
redhat
2 месяца назад

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.

CVSS3: 5.6
nvd
2 месяца назад

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.

CVSS3: 5.6
msrc
2 месяца назад

AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue

CVSS3: 5.6
github
2 месяца назад

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.

EPSS

Процентиль: 4%
0.00021
Низкий