CVE-2024-36350

MEDIUM

AMD EPYC and Ryzen Processors - Exposure of Sensitive Information via Transient Execution

Title source: llm
STIX 2.1

Description

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.

Scores

CVSS v3 5.6
EPSS 0.0003
EPSS Percentile 9.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1421
Status published
Products (27)
AMD/AMD EPYC™ 7003 Series Processors MilanPI 1.0.0.G + OS Updates
AMD/AMD EPYC™ 8004 Series Processors GenoaPI 1.0.0.E + OS Updates
AMD/AMD EPYC™ 9004 Series Processors GenoaPI 1.0.0.E + OS Updates
AMD/AMD EPYC™ 9V64H Processor MI300PI 1.0.0.7 + OS Updates
AMD/AMD EPYC™ Embedded 7003 Series Processors EmbMilanPI-SP3 1.0.0.A + OS updates
AMD/AMD EPYC™ Embedded 8004 Series Processors EmbGenoaPI-SP5 1.0.0.9 + OS updates
AMD/AMD EPYC™ Embedded 9004 Series Processors EmbGenoaPI-SP5 1.0.0.9 + OS updates
AMD/AMD EPYC™ Embedded 97X4 EmbGenoaPI-SP5 1.0.0.9 + OS updates
AMD/AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics ComboAM4v2PI 1.2.0.E + OS Updates
AMD/AMD Ryzen™ 5000 Series Desktop Processors ComboAM4v2PI 1.2.0.E + OS Updates
... and 17 more
Published Jul 08, 2025
Tracked Since Feb 18, 2026