cbcvebase.
CVE-2024-56721
published 2024-12-29

CVE-2024-56721: In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Terminate the erratum_1386_microcode array The erratum_1386_microcode array…

PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
13.6th percentile
In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Terminate the erratum_1386_microcode array The erratum_1386_microcode array requires an empty entry at the end. Otherwise x86_match_cpu_with_stepping() will continue iterate the array after it ended. Add an empty entry to erratum_1386_microcode to its end.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.3-1 (forky)linux 6.12.3-1 (forky)
linuxlinux
linuxlinux>= 29ba89f1895285f06c333546882e0c5ae9a6df23 < 82d6b82cf89d950982ac240ba068c3a7e1f23b0a82d6b82cf89d950982ac240ba068c3a7e1f23b0a
linuxlinux>= 29ba89f1895285f06c333546882e0c5ae9a6df23 < ccfee14f08b8699132b87bc6d78e0fa75bf094ddccfee14f08b8699132b87bc6d78e0fa75bf094dd
linuxlinux>= 29ba89f1895285f06c333546882e0c5ae9a6df23 < ff6cdc407f4179748f4673c39b0921503199a0adff6cdc407f4179748f4673c39b0921503199a0ad
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.10 < 6.11.116.11.11
linuxlinux_kernel>= 6.12 < 6.12.26.12.2

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.