Bug 2336412 (CVE-2024-36347) - CVE-2024-36347 kernel: hw:amd: Improper signature verification in AMD CPU ROM microcode patch loader
Summary: CVE-2024-36347 kernel: hw:amd: Improper signature verification in AMD CPU ROM...
Keywords:
Status: NEW
Alias: CVE-2024-36347
Deadline: 2025-03-05
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-01-08 15:42 UTC by OSIDB Bzimport
Modified: 2025-03-06 14:13 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-01-08 15:42:03 UTC
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with system administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.


Note You need to log in before you can comment on or make changes to this bug.