Improper Verification of Cryptographic Signature in AMD products - CVE-2024-36347

 

Improper Verification of Cryptographic Signature in AMD products - CVE-2024-36347

Published: May 21, 2025


Vulnerability identifier: #VU109619
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-36347
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper signature verification of x86 instruction execution. A local privileged user can load malicious microcode and execute it on the system.


Affected software

AMD Ryzen 7000 Series Desktop Processors
AMD Ryzen Threadripper PRO 3000WX Series Processors
AMD Ryzen 3000 Series Desktop processor
AMD EPYC Embedded 9004
AMD Ryzen Threadripper 3000 Series Processors
AMD EPYC Embedded 7003
AMD EPYC Embedded 7002
AMD EPYC 7001 Processors
AMD Ryzen Threadripper 7000 Series Processors
AMD Ryzen 8000 Series Processors with Radeon Graphics
AMD Ryzen 5000 Series Desktop processor
AMD Ryzen 4000 Series Desktop processors with Radeon graphics
Cray EX425
Dell G15 5535
Inspiron 14 5435
Inspiron 14 7435 2-in-1
Inspiron 16 5635
Inspiron 16 7635 2-in-1
Vostro 16 5635
Vostro 14 3435
Inspiron 15 3535
Vostro 15 3535
Dell G15 5525
Inspiron 14 5425
Inspiron 14 7425 2-in-1
Inspiron 16 5625
Vostro 5625
Vostro 14 3425
Vostro 15 3525
Inspiron 15 3525
Dell G15 5515
Alienware m15 Ryzen Edition R5
Inspiron 7415 2-in-1
Inspiron 5515
Inspiron 5415
Vostro 5415
Vostro 5515
Inspiron 24 5415 All-in-One
Inspiron 3505
Vostro 3405
Vostro 15 3515
Inspiron 15 3515
Alienware Aurora Ryzen Edition R14
HPE ProLiant XL225n Gen10 Plus 1U Node
HPE ProLiant XL645d Gen10 Plus Server
HPE ProLiant XL675d Gen10 Plus Server
Citrix XenServer
Cray EX235n
Cray EX4252
Ubuntu
Cray EX235a
linux (Ubuntu package)
linux-aws-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-xilinx (Ubuntu package)
linux-oracle (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-lowlatency (Ubuntu package)
linux-gcp-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-realtime (Ubuntu package)
linux-aws (Ubuntu package)
linux-realtime-6.17 (Ubuntu package)
linux-gcp (Ubuntu package)
linux-raspi (Ubuntu package)

How to mitigate CVE-2024-36347

Install updates from vendor's website.

AMD Ryzen 7000 Series Desktop Processors - addressed in versions 1.0.0.a, 1.1.0.3c, 1.2.0.3
AMD Ryzen Threadripper PRO 3000WX Series Processors - addressed in versions 1.0.0.B, 1.0.0.g
AMD Ryzen 3000 Series Desktop processor - addressed in versions 1.0.0.D, 1.2.0.E
AMD EPYC Embedded 9004 - update to 1.0.0.E
AMD Ryzen Threadripper 3000 Series Processors - update to 1.0.0.E
AMD EPYC Embedded 7003 - update to 1.0.0.F
AMD EPYC Embedded 7002 - update to 1.0.0.L
AMD EPYC 7001 Processors - update to 1.0.0.P
AMD Ryzen Threadripper 7000 Series Processors - addressed in versions 1.0.0.1k, 1.1.0.0i
AMD Ryzen 8000 Series Processors with Radeon Graphics - addressed in versions 1.1.0.3c, 1.2.0.3
AMD Ryzen 5000 Series Desktop processor - update to 1.2.0.E
AMD Ryzen 4000 Series Desktop processors with Radeon graphics - update to 1.2.0.E
Cray EX235n - update to 1.5.2
Cray EX425 - update to 1.7.7
Dell G15 5535 - update to 1.12.0
Inspiron 14 5435 - update to 1.15.0
Inspiron 14 7435 2-in-1 - update to 1.15.0
Inspiron 16 5635 - update to 1.15.0
Inspiron 16 7635 2-in-1 - update to 1.15.0
Vostro 16 5635 - update to 1.15.0
Vostro 14 3435 - update to 1.20.0
Inspiron 15 3535 - update to 1.20.0
Vostro 15 3535 - update to 1.20.0
Dell G15 5525 - update to 1.21.0
Inspiron 14 5425 - update to 1.21.0
Inspiron 14 7425 2-in-1 - update to 1.21.0
Inspiron 16 5625 - update to 1.21.0
Vostro 5625 - update to 1.21.0
Vostro 14 3425 - update to 1.25.0
Vostro 15 3525 - update to 1.25.0
Inspiron 15 3525 - update to 1.25.0
Dell G15 5515 - update to 1.25.0
Alienware m15 Ryzen Edition R5 - update to 1.26.0
Inspiron 7415 2-in-1 - update to 1.27.0
Inspiron 5515 - update to 1.27.0
Inspiron 5415 - update to 1.27.0
Vostro 5415 - update to 1.27.0
Vostro 5515 - update to 1.27.0
Inspiron 24 5415 All-in-One - update to 1.27.0
Inspiron 3505 - update to 1.29.0
Vostro 3405 - update to 1.29.0
Vostro 15 3515 - update to 1.30.0
Inspiron 15 3515 - update to 1.30.0
Cray EX235a - update to 2.1.0
Cray EX4252 - update to 2.1.0
Alienware Aurora Ryzen Edition R14 - update to 2.22.0
HPE ProLiant XL225n Gen10 Plus 1U Node - update to 3.60_01-16-2025
HPE ProLiant XL645d Gen10 Plus Server - update to 3.60_01-16-2025
HPE ProLiant XL675d Gen10 Plus Server - update to 3.60_01-16-2025
linux (Ubuntu package) - addressed in versions 6.8.0-110.110, 6.8.0-110.110.1, 6.8.0-110.110.1~22.04.1, 6.8.0-1037.40, 6.8.0-1050.56, 6.8.0-1051.51, 6.8.0-1052.55~22.04.1, 6.8.0-1054.57, 6.17.0-22.22, 6.17.0-1010.11
linux-aws-fips (Ubuntu package) - addressed in versions 6.8.0-110.110+fips2, 6.8.0-1052.55+fips1, 6.8.0-1054.57+fips1
linux-hwe-6.8 (Ubuntu package) - addressed in versions 6.8.0-110.110~22.04.1, 6.8.0-1051.51~22.04.1, 6.8.0-1052.56
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1022.22
linux-xilinx (Ubuntu package) - update to 6.8.0-1029.30
linux-oracle (Ubuntu package) - addressed in versions 6.8.0-1049.50, 6.8.0-1049.50~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1051.54, 6.8.0-1051.54~22.04.1
linux-nvidia-lowlatency (Ubuntu package) - update to 6.8.0-1051.54.1
linux-gcp-6.8 (Ubuntu package) - update to 6.8.0-1054.57~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1054.60, 6.17.0-1013.13, 6.17.0-1013.13~24.04.1, 6.17.0-1020.20
linux-azure-fips (Ubuntu package) - update to 6.8.0-1054.60+fips1
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2042.43
linux-realtime (Ubuntu package) - update to 6.8.1-1047.48
linux-aws (Ubuntu package) - addressed in versions 6.17.0-22.22~24.04.1, 6.17.0-1011.11, 6.17.0-1011.11~24.04.1, 6.17.0-1012.12, 6.17.0-1012.12~24.04.1
linux-realtime-6.17 (Ubuntu package) - update to 6.17.0-1010.11~24.04.1
linux-gcp (Ubuntu package) - addressed in versions 6.17.0-1012.12, 6.17.0-1012.12~24.04.1
linux-raspi (Ubuntu package) - update to 6.17.0-1014.14

External References

Related Security Bulletins