CVE-2024-36315
Last modified
CVE-2024-36315 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensitive information, potentially resulting in loss of confidentiality.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensitive information, potentially resulting in loss of confidentiality.
Metrics
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AMD | AMD EPYC™ Series 9004 Processors | All versions |
| AMD | AMD EPYC™Series 4004 Processors | All versions |
| AMD | AMD EPYC™ 8004 Series Processors | All versions |
| AMD | AMD Instinct™ MI300A Series Processors | All versions |
| AMD | AMD Ryzen™ Z1 Series Processors | All versions |
| AMD | AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics | All versions |
| AMD | AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics | All versions |
| AMD | AMD Ryzen™ 9000 Series Desktop Processors | All versions |
| AMD | AMD Ryzen™ 7000 Series Desktop Processors | All versions |
| AMD | AMD Ryzen™ 8000 Series Desktop Processors | All versions |
| AMD | AMD Ryzen™ 7000 Series Desktop Processors (formerly codenamed "Raphael") | All versions |
| AMD | AMD Ryzen™ 8000 Series Desktop Processors (formerly codenamed "Phoenix") | All versions |
| AMD | AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Genoa") | All versions |
| AMD | AMD EPYC™ Embedded 8004 Series Processors | All versions |
| AMD | AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Bergamo") | All versions |
| AMD | AMD Ryzen™ Embedded 8000 Series Processors | All versions |
| AMD | AMD Ryzen™ Embedded 7000 Series Processors | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2024-36315?
How severe is CVE-2024-36315?
How do I fix CVE-2024-36315?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-36305A security agent link following vulnerability in Trend Micro…7.8
- CVE-2024-36306A link following vulnerability in the Trend Micro Apex One a…5.5
- CVE-2024-36307A security agent link following vulnerability in Trend Micro…5.5
- CVE-2024-3631The HL Twitter WordPress plugin through 2014.1.18 does not h…4.3
- CVE-2024-36310Improper input validation in the SMM communications buffer c…4.6
- CVE-2024-36311A Time-of-check time-of-use (TOCTOU) race condition in the S…4.6
- CVE-2024-36316The integer overflow vulnerability within AMD Graphics drive…5.5
- CVE-2024-36319Debug code left active in AMD's Video Decoder Engine Firmwar…6.3
- CVE-2024-3632The Smart Image Gallery WordPress plugin before 1.0.19 does …6.8
- CVE-2024-36320Integer Overflow within atihdwt6.sys can allow a local attac…7
- CVE-2024-36321Unquoted search path within AIM-T Manageability Service can …7.3
- CVE-2024-36323Improper isolation of VCN-JPEG HW register space could allow…8.8
Are you affected by CVE-2024-36315?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
