GPU VulnDB

Database/Kernel, userspace & hypervisor

AMD CPU (EntrySign): Improper signature verification in the AMD CPU microcode patch loader

CVE-2024-36347Kernel, userspace & hypervisorcurated

Impact

Improper signature verification in the AMD CPU microcode patch loader - a ring-0 attacker can load arbitrary microcode, defeating SEV-SNP attestation

Who can reach it

Local ring-0 / compromised host; breaks confidential-VM guarantees

What to do

AGESA/BIOS firmware update + reboot across the fleet; SEV-SNP attestation reports from unpatched hosts cannot be trusted

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.