CVE-2024-36315 PUBLISHED

Assigner: AMD
Reserved: 23.05.2024 Published: 13.05.2026 Updated: 13.05.2026

Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensitive information, potentially resulting in loss of confidentiality.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.7

Product Status

Vendor AMD
Product AMD EPYC™ Series 9004 Processors
Versions Default: affected
  • Version GenoaPI_1.0.0.E is unaffected
Vendor AMD
Product AMD EPYC™Series 4004 Processors
Versions Default: affected
  • Version ComboAM5PI_1.0.0.a/ ComboAM5PI_1.1.0.3c/ ComboAM5PI_1.2.0.3 is unaffected
Vendor AMD
Product AMD EPYC™ 8004 Series Processors
Versions Default: affected
  • Version GenoaPI_1.0.0.E is unaffected
Vendor AMD
Product AMD Instinct™ MI300A Series Processors
Versions Default: affected
  • Version MI300PI 1.0.0.7 is unaffected
Vendor AMD
Product AMD Ryzen™ Z1 Series Processors
Versions Default: affected
  • Version ComboAM5PI_1.2.0.3 is unaffected
  • Version ComboAM5PI_1.1.0.3c is unaffected
  • Version ComboAM5PI_1.0.0.a is unaffected
Vendor AMD
Product AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics
Versions Default: affected
  • Version PhoenixPI-FP8-FP7_1.2.0.0 is unaffected
Vendor AMD
Product AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics
Versions Default: affected
  • Version DragonRangeFL1_1.0.0.3g is unaffected
Vendor AMD
Product AMD Ryzen™ 9000 Series Desktop Processors
Versions Default: affected
  • Version ComboAM5PI_1.2.0.3 is unaffected
Vendor AMD
Product AMD Ryzen™ 7000 Series Desktop Processors
Versions Default: affected
  • Version ComboAM5PI_1.0.0.a is unaffected
  • Version ComboAM5PI_1.1.0.3c is unaffected
  • Version ComboAM5PI_1.2.0.3 is unaffected
Vendor AMD
Product AMD Ryzen™ 8000 Series Desktop Processors
Versions Default: affected
  • Version ComboAM5PI_1.1.0.3c is unaffected
  • Version ComboAM5PI_1.2.0.3 is unaffected
Vendor AMD
Product AMD Ryzen™ 7000 Series Desktop Processors (formerly codenamed "Raphael")
Versions Default: affected
  • Version ComboAM5PI_1.3.0.0 is unaffected
Vendor AMD
Product AMD Ryzen™ 8000 Series Desktop Processors (formerly codenamed "Phoenix")
Versions Default: affected
  • Version ComboAM5PI_1.3.0.0 is unaffected
Vendor AMD
Product AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Genoa")
Versions Default: affected
  • Version EmbGenoaPI-SP5 1.0.0.D is unaffected
Vendor AMD
Product AMD EPYC™ Embedded 8004 Series Processors
Versions Default: affected
  • Version EmbGenoaPI-SP5 1.0.0.D is unaffected
Vendor AMD
Product AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Bergamo")
Versions Default: affected
  • Version EmbGenoaPI-SP5 1.0.0.D is unaffected
Vendor AMD
Product AMD Ryzen™ Embedded 8000 Series Processors
Versions Default: affected
  • Version EmbeddedPhoenixPI-FP7r2_1.0.0.3 is unaffected
Vendor AMD
Product AMD Ryzen™ Embedded 7000 Series Processors
Versions Default: affected
  • Version EmbeddedAM5PI 1.0.0.5 is unaffected

References

Problem Types

  • CWE-693 Protection Mechanism Failure CWE