CVE-2024-36349
A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage.
Scoring
- Severity
- LOW
- CVSS base score
- 3.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- EPSS probability
- 0.18%
- CWE
- CWE-1420
- Published
- 2025-07-08
- Last modified
- 2026-03-13
Affected products
- AMD AMD EPYC™ 7002 Series Processors
- AMD AMD EPYC™ 7003 Series Processors
- AMD AMD EPYC™ 9004 Series Processors
- AMD AMD EPYC™ 8004 Series Processors
- AMD AMD EPYC™ 4004 Series Processors
- AMD AMD EPYC™ 9V64H Processor
- AMD AMD Ryzen™ 5000 Series Desktop Processors
- AMD AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics
Weakness type
Related vulnerabilities
- CVE-2025-54505 — A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to...
- CVE-2025-27572 — Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor...
- CVE-2024-36348 — A transient execution vulnerability in some AMD processors may allow a user process to infer the...