Database/Kernel, userspace & hypervisor
AMD CPU (EntrySign): Improper signature verification in the AMD CPU microcode patch loader
CVSS 7.5CVE-2024-36347Kernel, userspace & hypervisorcurated
Impact
Improper signature verification in the AMD CPU microcode patch loader - a ring-0 attacker can load arbitrary microcode, defeating SEV-SNP attestation
Who can reach it
Local ring-0 / compromised host; breaks confidential-VM guarantees
What to do
AGESA/BIOS firmware update + reboot across the fleet; SEV-SNP attestation reports from unpatched hosts cannot be trusted
References
Related entries
- VMware vCenter: Privilege escalation to root on vCenter via a crafted network packetCVE-2024-38813 · VMware vCenterHigh
- Linux kernel NVMe target core (controller teardown racing queue-pair establishment): An initiator that disconnectsCVE-2024-42152 · Linux kernel NVMe target core (controller teardown racing queue-pair establishment)High
- Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure): When command allocation for a new queueCVE-2024-46737 · Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure)High
- Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return): The length field in the CLC header isCVE-2024-57791 · Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return)High
- QEMU (NBD server): Improper synchronisation during socket closure - DoS of the QEMU NBD serverCVE-2024-7409 · QEMU (NBD server)High
- QEMU: use-after-free in the VNC WebSocket handshake crashes the VM process before client authenticationCVE-2025-11234 · QEMU QIOChannelWebsock (VNC WebSocket handshake)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.