cbcvebase.

Debian Amd64-Microcode vulnerabilities

13 known vulnerabilities affecting debian/amd64-microcode.

Total CVEs
13
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM10

Vulnerabilities

Page 1 of 1
CVE-2017-5715P2MEDIUMCVSS 5.6PoCfixed in amd64-microcode 3.20180515.1 (bookworm)2017
CVE-2017-5715 [MEDIUM] CVE-2017-5715: amd64-microcode - Systems with microprocessors utilizing speculative execution and indirect branch... Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. Scope: local bookworm: resolved (fixed in 3.20180515.1) bullseye: resolved (fixed in 3.20180515.1) forky: resolved (fixed in 3.20180515.1) sid: resolved
debian
CVE-2023-31315P3HIGHCVSS 7.5fixed in amd64-microcode 3.20240710.2~deb12u1 (bookworm)2023
CVE-2023-31315 [HIGH] CVE-2023-31315: amd64-microcode - Improper validation in a model specific register (MSR) could allow a malicious p... Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution. Scope: local bookworm: resolved (fixed in 3.20240710.2~deb12u1) bullseye: resolved (fixed in 3.20240710.2~deb11u1) forky: resolved (fixed in 3.20240710
debian
CVE-2024-56161P3HIGHCVSS 7.2fixed in amd64-microcode 3.20250311.1~deb12u1 (bookworm)2024
CVE-2024-56161 [HIGH] CVE-2024-56161: amd64-microcode - Improper signature verification in AMD CPU ROM microcode patch loader may allow ... Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. Scope: local bookworm: resolved (fixed in 3.20250311.1~deb12u1) bullseye: resolved (fixed in 3.2025
debian
CVE-2023-20592P4MEDIUMCVSS 6.5fixed in amd64-microcode 3.20230719.1~deb12u1 (bookworm)2023
CVE-2023-20592 [MEDIUM] CVE-2023-20592: amd64-microcode - Improper or unexpected behavior of the INVD instruction in some AMD CPUs may all... Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity. Scope: local bookworm: resolved (fixed in 3.20230719.1~deb12u1) bullseye: resolved (fixed in 3.20230719.1~d
debian
CVE-2025-62626P4HIGHCVSS 7.2fixed in amd64-microcode 3.20251202.1 (forky)2025
CVE-2025-62626 [HIGH] CVE-2025-62626: amd64-microcode - Improper handling of insufficient entropy in the AMD CPUs could allow a local at... Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 3.20251202.1) sid: resolved (fixed in 3.20251202.1) trixie: open
debian
CVE-2023-20593P4MEDIUMCVSS 5.5fixed in amd64-microcode 3.20230719.1~deb12u1 (bookworm)2023
CVE-2023-20593 [MEDIUM] CVE-2023-20593: amd64-microcode - An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may a... An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. Scope: local bookworm: resolved (fixed in 3.20230719.1~deb12u1) bullseye: resolved (fixed in 3.20230719.1~deb11u1) forky: resolved (fixed in 3.20230719.1) sid: resolved (fixed in 3.20230719.1) trixie: resolved (fixed
debian
CVE-2023-20569P4MEDIUMCVSS 4.7fixed in amd64-microcode 3.20230719.1~deb12u1 (bookworm)2023
CVE-2023-20569 [MEDIUM] CVE-2023-20569: amd64-microcode - A side channel vulnerability on some of the AMD CPUs may allow an attacker to in... A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. Scope: local bookworm: resolved (fixed in 3.20230719.1~deb12u1) bullseye: resolved (fixed in 3.20230719.1~deb11u1) f
debian
CVE-2019-9836P4MEDIUMCVSS 5.3fixed in amd64-microcode 3.20220411.1 (bookworm)2019
CVE-2019-9836 [MEDIUM] CVE-2019-9836: amd64-microcode - Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform S... Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation. Scope: local bookworm: resolved (fixed in 3.20220411.1) bullseye: resolved (fixed in 3.20230719.1~deb11u1) forky: resolved (fixed in 3.20220411.1) s
debian
CVE-2024-36350P4MEDIUMCVSS 5.6fixed in amd64-microcode 3.20251202.1 (forky)2024
CVE-2024-36350 [MEDIUM] CVE-2024-36350: amd64-microcode - A transient execution vulnerability in some AMD processors may allow an attacker... A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 3.20251202.1) sid: resolved (fixed in 3.20251202.1) trixie: open
debian
CVE-2024-36357P4MEDIUMCVSS 5.6fixed in amd64-microcode 3.20251202.1 (forky)2024
CVE-2024-36357 [MEDIUM] CVE-2024-36357: amd64-microcode - A transient execution vulnerability in some AMD processors may allow an attacker... A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 3.20251202.1) sid: resolved (fixed in 3.20251202.1) trixie: open
debian
CVE-2023-20584P4MEDIUMCVSS 5.3fixed in amd64-microcode 3.20240820.1~deb12u1 (bookworm)2023
CVE-2023-20584 [MEDIUM] CVE-2023-20584: amd64-microcode - IOMMU improperly handles certain special address ranges with invalid device tabl... IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity. Scope: local bookworm: resolved (fixed in 3.20240820.1~deb12u1) bullseye: resolved
debian
CVE-2025-29943P4MEDIUMCVSS 4.6fixed in amd64-microcode 3.20251202.1 (forky)2025
CVE-2025-29943 [MEDIUM] CVE-2025-29943: amd64-microcode - Write what were condition within AMD CPUs may allow an admin-privileged attacker... Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 3.20251202.1) sid: resolved (fixed in 3.20251202.1) trixie: open
debian
CVE-2023-31356P4MEDIUMCVSS 4.4fixed in amd64-microcode 3.20240820.1~deb12u1 (bookworm)2023
CVE-2023-31356 [MEDIUM] CVE-2023-31356: amd64-microcode - Incomplete system memory cleanup in SEV firmware could allow a privileged attack... Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity. Scope: local bookworm: resolved (fixed in 3.20240820.1~deb12u1) bullseye: resolved (fixed in 3.20240820.1~deb11u1) forky: resolved (fixed in 3.20240820.1) sid: resolved (fixed in 3.20240820.1
debian
Debian Amd64-Microcode vulnerabilities | cvebase