CVE-2024-36315

Publication date 17 September 2026

Last updated 18 September 2026


Ubuntu priority

Description

Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensitive information, potentially resulting in loss of confidentiality.

Read the notes from the security team

Status

Package Ubuntu Release Status
amd64-microcode 26.04 LTS resolute
Fixed 3.20251202.1ubuntu1
25.10 questing
Fixed 3.20251202.1ubuntu0.25.10.1
24.04 LTS noble
Fixed 3.20251202.1ubuntu0.24.04.1
22.04 LTS jammy
Vulnerable
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable
16.04 LTS xenial
Vulnerable
14.04 LTS trusty Ignored no real-world users

Notes


rodrigo-zaiden

Only affects EPYC fam 19h, Genoa. AMD released ucode patches for (AMD-SB-3030, EPYC/fam19h): EPYC 8004 A2: 0x0AA00216 / EPYC 9004 A2: 0x0AA00219 / B1: 0x0A101154 / B2: 0x0A10124F These patches are included in upstream Version: 2025-07-29 (commit 3768c184): Microcode patches in microcode_amd_fam19h.bin: Family=0x19 Model=0x11 Stepping=0x01: Patch=0x0a101158 Length=5568 bytes Family=0x19 Model=0x11 Stepping=0x02: Patch=0x0a101253 Length=5568 bytes Family=0x19 Model=0xa0 Stepping=0x02: Patch=0x0aa0021c Length=5568 bytes The shipped patch revisions superseed the bulletin minimums (0x0a101158 >= 0x0a101154; 0x0a101253 >= 0x0a10124f; 0x0aa0021c >= both 0x0aa00216 and 0x0aa00219) and are present in version 3.20251202.1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
amd64-microcode

Severity score breakdown

CVSS version: CVSS v4.0

Base score 5.7 · Medium

Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N


Access our resources on patching vulnerabilities