CVE-2024-36315
Publication date 17 September 2026
Last updated 18 September 2026
Ubuntu priority
Description
Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensitive information, potentially resulting in loss of confidentiality.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| amd64-microcode | 26.04 LTS resolute |
Fixed 3.20251202.1ubuntu1
|
| 24.04 LTS noble |
Fixed 3.20251202.1ubuntu0.24.04.1
|
|
| 22.04 LTS jammy |
Vulnerable
|
|
| 20.04 LTS focal |
Vulnerable
|
|
| 18.04 LTS bionic |
Vulnerable
|
|
| 16.04 LTS xenial |
Vulnerable
|
|
| 14.04 LTS trusty | Ignored no real-world users |
Notes
rodrigo-zaiden
Only affects EPYC fam 19h, Genoa. AMD released ucode patches for (AMD-SB-3030, EPYC/fam19h): EPYC 8004 A2: 0x0AA00216 / EPYC 9004 A2: 0x0AA00219 / B1: 0x0A101154 / B2: 0x0A10124F These patches are included in upstream Version: 2025-07-29 (commit 3768c184): Microcode patches in microcode_amd_fam19h.bin: Family=0x19 Model=0x11 Stepping=0x01: Patch=0x0a101158 Length=5568 bytes Family=0x19 Model=0x11 Stepping=0x02: Patch=0x0a101253 Length=5568 bytes Family=0x19 Model=0xa0 Stepping=0x02: Patch=0x0aa0021c Length=5568 bytes The shipped patch revisions superseed the bulletin minimums (0x0a101158 >= 0x0a101154; 0x0a101253 >= 0x0a10124f; 0x0aa0021c >= both 0x0aa00216 and 0x0aa00219) and are present in version 3.20251202.1
Severity score breakdown
CVSS version: CVSS v4.0
Base score
5.7 · Medium
Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N