Ubuntu Critical Linux Kernel Vulnerabilities Affecting AMD Zen Processors
Article Content
- •EntrySign (CVE-2024-36347) allows privileged access to load malicious CPU microcode.
- •Vulnerabilities affect multiple architectures, including MIPS, PowerPC, and x86.
- •Immediate patching is recommended to mitigate risks associated with these vulnerabilities.
Multiple vulnerabilities were discovered in the Linux kernel, primarily affecting AMD Zen processors. The most notable flaw, known as EntrySign (CVE-2024-36347), allows privileged attackers to bypass CPU microcode signature verification, potentially leading to integrity and confidentiality breaches. This vulnerability impacts various subsystems across MIPS, PowerPC, and x86 architectures, among others. The updates released address several security issues, but the risk remains significant due to the potential for exploitation. The vulnerabilities were reported by researchers Josh Eads, Kristoffer Janke, Eduardo Vela Nava, Tavis Ormandy, and Matteo Rizzo. Users are advised to apply the latest patches to mitigate these risks. The vulnerabilities were published on June 27, 2025, and have been a focus of recent security advisories. The situation is ongoing as new updates are released to address these flaws.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (30)
Following this threat?
Track CVE-2024-36347 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…