{"id":"USN-8475-1","summary":"amd64-microcode vulnerabilities","details":"Oleksii Oleksenko, Cedric Fournet, Jana Hofmann, Boris Köpf, Stavros Volos,\nand Flavien Solt discovered that some AMD processors may allow an attacker\nto infer data from previous stores, potentially resulting in the leakage of\nprivileged information. A local attacker could possibly use this to expose\nsensitive information. (CVE-2024-36350, CVE-2024-36357)\n\nIt was discovered that some AMD Zen 5 processors supporting RDSEED\ninstruction did not properly handle entropy, potentially resulting in the\nconsumption of insufficiently random values. A local attacker could\npossibly use this issue to influence the values returned by the RDSEED\ninstruction causing loss of confidentiality and integrity. (CVE-2025-62626)","modified":"2026-06-25T23:59:17.431281671Z","published":"2026-06-25T15:09:58Z","related":["UBUNTU-CVE-2024-36350","UBUNTU-CVE-2024-36357","UBUNTU-CVE-2025-62626"],"upstream":["CVE-2024-36350","CVE-2024-36357","CVE-2025-62626","UBUNTU-CVE-2024-36350","UBUNTU-CVE-2024-36357","UBUNTU-CVE-2025-62626"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8475-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-36350"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-36357"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-62626"}],"affected":[{"package":{"name":"amd64-microcode","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/amd64-microcode?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.20251202.1ubuntu0.24.04.1"}]}],"versions":["3.20230808.1.1ubuntu1","3.20231019.1ubuntu1","3.20231019.1ubuntu2","3.20231019.1ubuntu2.1","3.20250311.1ubuntu0.24.04.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"3.20251202.1ubuntu0.24.04.1","binary_name":"amd64-microcode"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:24.04:LTS","cves":[{"id":"CVE-2024-36350","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-36357","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-62626"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8475-1.json"}},{"package":{"name":"amd64-microcode","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/amd64-microcode?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.20251202.1ubuntu0.25.10.1"}]}],"versions":["3.20240820.1ubuntu1","3.20250311.1ubuntu1","3.20250708.1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.20251202.1ubuntu0.25.10.1","binary_name":"amd64-microcode"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:25.10","cves":[{"id":"CVE-2024-36350","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-36357"},{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-62626"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8475-1.json"}}],"schema_version":"1.7.5"}