BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2025
CVE-2024-36349High confidence

A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage

AMD · AMD EPYC™ 7002 Series Processors

3.8LowCVSS 3.1
Recommended action
Scheduled

Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.

Fix not verified
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityLowOperational priority:Low, unchanged from published severity.unchanged

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • Exploitation requires an existing local or physical foothold with privileges.
  • EPSS is 0.18% for the current model date.

Compensating controls

  • Restrict local access and enforce least privilege on affected hosts.
  • Monitor vendor guidance and exploitation sources for a material change.

Verification

  1. Confirm that the asset runs AMD AMD EPYC™ 7002 Series Processors and falls inside the recorded affected range.
  2. Recheck the vendor advisory before scheduling a change because no verified fixed version is currently retained.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: No default targetRemediation target: Normal maintenance

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Distribution package intelligence

Release-specific package status

Debian findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

4 package states
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Debian trixietrixie · sourceamd64-microcodeAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 5 Oct 2026
Debian bookwormbookworm · sourceamd64-microcodeAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 5 Oct 2026
Debian forkyforky · sourceamd64-microcodeAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 5 Oct 2026
Debian sidsid · sourceamd64-microcodeAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 5 Oct 2026
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2024-54762

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionScheduled

Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.

Fix not verified
01

What, why and how

A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage.

What

A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage.

Why

A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.

How

An attacker operating through local access may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage.

Why

A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.

How

An attacker operating through local access may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
local access → Exposure of Sensitive Information during Transient Execution → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Local
Privileges required
Low: a basic authenticated account is required
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Changed: exploitation can affect a different security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-1420 ↗

CWE-1420: Exposure of Sensitive Information during Transient Execution. A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVLocalAttack vector: The attacker needs local access to the vulnerable system.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRLowPrivileges required: The attacker needs basic user-level privileges.UINoneUser interaction: No action by another user is required.SChangedScope: The attack can affect a component governed by a different security authority.CLowConfidentiality impact: A successful attack can cause a limited loss.INoneIntegrity impact: No direct loss is represented by this metric.ANoneAvailability impact: No direct loss is represented by this metric.
Post-exploitation / living off the land
The issue can support a local privilege or sandbox boundary transition; normal system utilities may then be available in the gained context.
CWE-1420
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-2025-1502AMD Prozessor: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen

Ein lokaler Angreifer kann mehrere Schwachstellen in AMD Prozessor ausnutzen, um Informationen offenzulegen.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0225Multiples vulnérabilités dans le noyau Linux de SUSE

d?id=CVE-2023-54324 Référence CVE CVE-2023-54325 https://www.cve.org/CVERecord?id=CVE-2023-54325 Référence CVE CVE-2023-54326 https://www.cve.org/CVERecord?id=CVE-2023-54326 Référence CVE CVE-2024-26581 https://www.cve.org/CVERecord?id=CVE-2024-26581 Référence CVE CVE-2024-26832 https://www.cve.org/CVERecord?id=CVE-2024-26832 Référence CVE CVE-2024-26944 https://www.cve.org/CVERecord?id=CVE-2024-26944 Référence CVE CVE-2024-27005 https://www.cve.org/CVERecord?id=CVE-2024-27005 Référence CVE CVE-2024-28956 https://www.cve.org/CVERecord?id=CVE-2024-28956 Référence CVE CVE-2024-36348 https://www.cve.org/CVERecord?id=CVE-2024-36348 Référence CVE CVE-2024-36349 https://www.cve.org/CVERecord?id=CVE-2024-36349 Référence CVE CVE-2024-36350 https://www.cve.org/CVERecord?id=CVE-2024-36350 Référence CVE CVE-2024-36357 https://www.cve.org/CVERecord?id=CVE-2024-36357 Référence CVE CVE-2024-42103 https://www.cve.org/CVERecord?id=CVE-2024-42103 Référence CVE CVE-2024-44987 https://www.cve.org/CVERecord?id=CVE-2024-44987 Référence CVE CVE-2024-46854 https://www.cve.org/CVERecord?id=CVE-2024-46854 Référence CVE CVE-2024-50143 https://www.cve.org/CVERecord?id=CVE-2024-50143 Référence CVE CVE-2024-53070 https://www.cve.org/CVERecord?id=CVE-2024-53070 Référence CVE CVE-2024-53149 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0170Multiples vulnérabilités dans le noyau Linux de SUSE

d?id=CVE-2023-54325 Référence CVE CVE-2023-54326 https://www.cve.org/CVERecord?id=CVE-2023-54326 Référence CVE CVE-2024-26581 https://www.cve.org/CVERecord?id=CVE-2024-26581 Référence CVE CVE-2024-26661 https://www.cve.org/CVERecord?id=CVE-2024-26661 Référence CVE CVE-2024-26832 https://www.cve.org/CVERecord?id=CVE-2024-26832 Référence CVE CVE-2024-26935 https://www.cve.org/CVERecord?id=CVE-2024-26935 Référence CVE CVE-2024-27005 https://www.cve.org/CVERecord?id=CVE-2024-27005 Référence CVE CVE-2024-28956 https://www.cve.org/CVERecord?id=CVE-2024-28956 Référence CVE CVE-2024-36348 https://www.cve.org/CVERecord?id=CVE-2024-36348 Référence CVE CVE-2024-36349 https://www.cve.org/CVERecord?id=CVE-2024-36349 Référence CVE CVE-2024-36350 https://www.cve.org/CVERecord?id=CVE-2024-36350 Référence CVE CVE-2024-36357 https://www.cve.org/CVERecord?id=CVE-2024-36357 Référence CVE CVE-2024-36903 https://www.cve.org/CVERecord?id=CVE-2024-36903 Référence CVE CVE-2024-41007 https://www.cve.org/CVERecord?id=CVE-2024-41007 Référence CVE CVE-2024-42103 https://www.cve.org/CVERecord?id=CVE-2024-42103 Référence CVE CVE-2024-44987 https://www.cve.org/CVERecord?id=CVE-2024-44987 Référence CVE CVE-2024-50040 https://www.cve.org/CVERecord?id=CVE-2024-50040 Référence CVE CVE-2024-50143 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0759Multiples vulnérabilités dans le noyau Linux de SUSE

in de sécurité SUSE SUSE-SU-2025:20625-1 du 25 août 2025 https://www.suse.com/support/update/announcement/2025/suse-su-202520625-1 Bulletin de sécurité SUSE SUSE-SU-2025:20626-1 du 25 août 2025 https://www.suse.com/support/update/announcement/2025/suse-su-202520626-1 Bulletin de sécurité SUSE SUSE-SU-2025:03023-1 du 29 août 2025 https://www.suse.com/support/update/announcement/2025/suse-su-202503023-1 Référence CVE CVE-2019-11135 https://www.cve.org/CVERecord?id=CVE-2019-11135 Référence CVE CVE-2024-36028 https://www.cve.org/CVERecord?id=CVE-2024-36028 Référence CVE CVE-2024-36348 https://www.cve.org/CVERecord?id=CVE-2024-36348 Référence CVE CVE-2024-36349 https://www.cve.org/CVERecord?id=CVE-2024-36349 Référence CVE CVE-2024-36350 https://www.cve.org/CVERecord?id=CVE-2024-36350 Référence CVE CVE-2024-36357 https://www.cve.org/CVERecord?id=CVE-2024-36357 Référence CVE CVE-2024-44963 https://www.cve.org/CVERecord?id=CVE-2024-44963 Référence CVE CVE-2024-53125 https://www.cve.org/CVERecord?id=CVE-2024-53125 Référence CVE CVE-2024-56664 https://www.cve.org/CVERecord?id=CVE-2024-56664 Référence CVE CVE-2024-56742 https://www.cve.org/CVERecord?id=CVE-2024-56742 Référence CVE CVE-2024-57947 https://www.cve.org/CVERecord?id=CVE-2024-57947 Référence CVE CVE-2025-21702 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0745Multiples vulnérabilités dans le noyau Linux de SUSE

in de sécurité SUSE SUSE-SU-2025:02996-1 du 27 août 2025 https://www.suse.com/support/update/announcement/2025/suse-su-202502996-1 Bulletin de sécurité SUSE SUSE-SU-2025:02997-1 du 27 août 2025 https://www.suse.com/support/update/announcement/2025/suse-su-202502997-1 Bulletin de sécurité SUSE SUSE-SU-2025:03011-1 du 28 août 2025 https://www.suse.com/support/update/announcement/2025/suse-su-202503011-1 Référence CVE CVE-2019-11135 https://www.cve.org/CVERecord?id=CVE-2019-11135 Référence CVE CVE-2024-36028 https://www.cve.org/CVERecord?id=CVE-2024-36028 Référence CVE CVE-2024-36348 https://www.cve.org/CVERecord?id=CVE-2024-36348 Référence CVE CVE-2024-36349 https://www.cve.org/CVERecord?id=CVE-2024-36349 Référence CVE CVE-2024-36350 https://www.cve.org/CVERecord?id=CVE-2024-36350 Référence CVE CVE-2024-36357 https://www.cve.org/CVERecord?id=CVE-2024-36357 Référence CVE CVE-2024-39298 https://www.cve.org/CVERecord?id=CVE-2024-39298 Référence CVE CVE-2024-42134 https://www.cve.org/CVERecord?id=CVE-2024-42134 Référence CVE CVE-2024-44963 https://www.cve.org/CVERecord?id=CVE-2024-44963 Référence CVE CVE-2024-49861 https://www.cve.org/CVERecord?id=CVE-2024-49861 Référence CVE CVE-2024-49996 https://www.cve.org/CVERecord?id=CVE-2024-49996 Référence CVE CVE-2024-56742 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0723Multiples vulnérabilités dans le noyau Linux de SUSE

d?id=CVE-2023-53117 Référence CVE CVE-2023-53118 https://www.cve.org/CVERecord?id=CVE-2023-53118 Référence CVE CVE-2023-53146 https://www.cve.org/CVERecord?id=CVE-2023-53146 Référence CVE CVE-2024-26643 https://www.cve.org/CVERecord?id=CVE-2024-26643 Référence CVE CVE-2024-26831 https://www.cve.org/CVERecord?id=CVE-2024-26831 Référence CVE CVE-2024-26974 https://www.cve.org/CVERecord?id=CVE-2024-26974 Référence CVE CVE-2024-26982 https://www.cve.org/CVERecord?id=CVE-2024-26982 Référence CVE CVE-2024-36028 https://www.cve.org/CVERecord?id=CVE-2024-36028 Référence CVE CVE-2024-36348 https://www.cve.org/CVERecord?id=CVE-2024-36348 Référence CVE CVE-2024-36349 https://www.cve.org/CVERecord?id=CVE-2024-36349 Référence CVE CVE-2024-36350 https://www.cve.org/CVERecord?id=CVE-2024-36350 Référence CVE CVE-2024-36357 https://www.cve.org/CVERecord?id=CVE-2024-36357 Référence CVE CVE-2024-36972 https://www.cve.org/CVERecord?id=CVE-2024-36972 Référence CVE CVE-2024-36978 https://www.cve.org/CVERecord?id=CVE-2024-36978 Référence CVE CVE-2024-42134 https://www.cve.org/CVERecord?id=CVE-2024-42134 Référence CVE CVE-2024-42265 https://www.cve.org/CVERecord?id=CVE-2024-42265 Référence CVE CVE-2024-43869 https://www.cve.org/CVERecord?id=CVE-2024-43869 Référence CVE CVE-2024-44963 https://www.cve.org/CVERecord?id=

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Fix not verified
Affected
  • AMD EPYC™ 7002 Series Processors: all
  • AMD EPYC™ 7003 Series Processors: all
  • AMD EPYC™ 9004 Series Processors: all
  • AMD EPYC™ 8004 Series Processors: all
  • AMD EPYC™ 4004 Series Processors: all
  • AMD EPYC™ 9V64H Processor: all
  • AMD Ryzen™ 5000 Series Desktop Processors: all
  • AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics: all
  • AMD Ryzen™ 3000 Series Desktop Processors: all
  • AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics: all
  • AMD Ryzen™ 7000 Series Desktop Processors: all
  • AMD Ryzen™ 4000 Series Desktop Processor with Radeon™ Graphics: all
  • AMD Ryzen™ 8000 Series Processor with Radeon™ Graphics: all
  • AMD Ryzen™ Threadripper™ 3000 Series Processors: all
  • AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors: all
  • AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors: all
  • AMD Ryzen™ Threadripper™ PRO 5000WX- Series Desktop Processors: all
  • AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics: all
  • AMD Ryzen™ 6000 Series Processor with Radeon™ Graphics: all
  • AMD Ryzen™ 7035 Series Processor with Radeon™ Graphics: all
  • AMD Ryzen™ 7000 Series Processors with Radeon™ Graphics: all
  • AMD Ryzen™ 7040 Series Processors with Radeon™ Graphics: all
  • AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics: all
  • AMD Ryzen™ 7000 Series Mobile Processors: all
  • AMD EPYC™ Embedded 7002 Series Processors: all
  • AMD EPYC™ Embedded 7003 Series Processors: all
  • AMD EPYC™ Embedded 8004 Series Processors: all
  • AMD EPYC™ Embedded 9004 Series Processors: all
  • AMD Ryzen™ Embedded 5000 Series Processors: all
  • AMD Ryzen™ Embedded 7000 Series Processors: all
  • AMD Ryzen™ Embedded V2000 Series Processors: all
  • AMD Ryzen™ Embedded V3000 Series Processors: all
  • AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics: all
  • AMD Ryzen™ 3000 Series Mobile Processor with Radeon™ Graphics: all
  • AMD EPYC™ Embedded 3000 Series Processors: all
  • AMD Ryzen™ Embedded R1000 Series Processors: all
  • AMD Ryzen™ Embedded R2000 Series Processors: all
  • AMD Ryzen™ Embedded V1000 Series Processors: all
Fixed
No fixed version is explicitly recorded in the structured CVE data.
Action
No verified patch reference is present in the current structured sources. Check the vendor advisory before making a change.
Workaround
No verified workaround is recorded. Limit untrusted access and use least privilege until authoritative guidance is available.
04

Evidence and provenance

Published 8 Jul 2025 · Last source change 9 Jul 2025, 14:00 UTC · CWE-1420 · Exposure of Sensitive Information during Transient Execution

CVE recordCVE.org · 5.1
CVSS sourceCNA
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2024-54762
Product sourceCNA
Remediation sourceCVE/CNA references
CWE sourceCNA
NVD statusNVD not scheduled

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗

No material field changes have been recorded since change tracking began. Routine source refreshes and cosmetic edits are intentionally excluded.

Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2024-36349 · cve.blacktree.nl