Improper Verification of Cryptographic Signature in AMD products - CVE-2024-56161

 

Improper Verification of Cryptographic Signature in AMD products - CVE-2024-56161

Published: February 4, 2025


Vulnerability identifier: #VU103603
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-56161
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper verification of cryptographic signature in AMD CPU ROM microcode patch loader. A local privileged user can load a malicious CPU microcode and escalate privileges on the system.


Affected software

4th Gen AMD EPYC Processors
3rd Gen AMD EPYC Processors
1st Gen AMD EPYC Processors
2nd Gen AMD EPYC Processors
AMD EPYC Embedded 7003
AMD EPYC Embedded 7002
AMD EPYC Embedded 9004
Dell EMC XC Core XC7525
PowerEdge C6615
Cray EX425
XC Core XC7625
PowerEdge R6615
PowerEdge R7615
PowerEdge R6625
PowerEdge R7625
HPE ProLiant XL675d Gen10 Plus Server
HPE ProLiant XL645d Gen10 Plus Server
HPE ProLiant XL225n Gen10 Plus 1U Node
PowerEdge R7425
PowerEdge R7415
PowerEdge R6515
PowerEdge R6525
PowerEdge R7515
PowerEdge R7525
PowerEdge C6525
PowerEdge XE8545
PowerEdge R6415
Cray EX235n
Cray EX4252
openEuler
Ubuntu
Cray EX235a
amd64-microcode (Ubuntu package)
linux-firmware-ti-connectivity
linux-firmware-netronome
linux-firmware-mrvl
linux-firmware-mediatek
linux-firmware-libertas
linux-firmware-iwlwifi
linux-firmware-cypress
linux-firmware-ath
linux-firmware

How to mitigate CVE-2024-56161

Install updates from vendor's website.

4th Gen AMD EPYC Processors - update to GenoaPI 1.0.0.E
3rd Gen AMD EPYC Processors - update to MilanPI 1.0.0.F
1st Gen AMD EPYC Processors - update to NaplesPI 1.0.0.P
2nd Gen AMD EPYC Processors - update to RomePI 1.0.0.L
AMD EPYC Embedded 7003 - update to 1.0.0.A
AMD EPYC Embedded 7002 - update to 1.0.0.D
AMD EPYC Embedded 9004 - update to 1.0.0.9
Cray EX235n - update to 1.5.2
PowerEdge C6615 - update to 1.6.2
Cray EX425 - update to 1.7.7
XC Core XC7625 - update to 1.11.2
PowerEdge R6615 - update to 1.11.2
PowerEdge R7615 - update to 1.11.2
PowerEdge R6625 - update to 1.11.2
PowerEdge R7625 - update to 1.11.2
Cray EX235a - update to 2.1.0
Cray EX4252 - update to 2.1.0
HPE ProLiant XL675d Gen10 Plus Server - update to 3.60_01-16-2025
HPE ProLiant XL645d Gen10 Plus Server - update to 3.60_01-16-2025
HPE ProLiant XL225n Gen10 Plus 1U Node - update to 3.60_01-16-2025
amd64-microcode (Ubuntu package) - addressed in versions 3.20250311.1ubuntu0.24.04.1, 3.20250311.1ubuntu0.24.10.1, 3.20250311.1ubuntu0.25.04.1
linux-firmware-ti-connectivity - update to 20250311-1
linux-firmware-netronome - update to 20250311-1
linux-firmware-mrvl - update to 20250311-1
linux-firmware-mediatek - update to 20250311-1
linux-firmware-libertas - update to 20250311-1
linux-firmware-iwlwifi - update to 20250311-1
linux-firmware-cypress - update to 20250311-1
linux-firmware-ath - update to 20250311-1
linux-firmware - update to 20250311-1

External References

Related Security Bulletins