Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests.
Metrics
Affected Vendors & Products
References
History
Sun, 07 Sep 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Amd
Amd epyc Amd epyc 7003 Amd epyc 8004 Amd epyc 9004 Amd epyc Embedded 7003 Amd epyc Embedded 9004 Amd ryzen 5000 Series Desktop Processors Amd ryzen 5000 Series Mobile Processors With Radeon Graphics Amd ryzen 6000 Series Processors With Radeon Graphics Amd ryzen 7000 Series Desktop Processors Amd ryzen 7030 Series Mobile Processors With Radeon Graphics |
|
Vendors & Products |
Amd
Amd epyc Amd epyc 7003 Amd epyc 8004 Amd epyc 9004 Amd epyc Embedded 7003 Amd epyc Embedded 9004 Amd ryzen 5000 Series Desktop Processors Amd ryzen 5000 Series Mobile Processors With Radeon Graphics Amd ryzen 6000 Series Processors With Radeon Graphics Amd ryzen 7000 Series Desktop Processors Amd ryzen 7030 Series Mobile Processors With Radeon Graphics |
Fri, 05 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 05 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests. | |
Weaknesses | CWE-459 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: AMD
Published: 2025-09-05T12:58:39.312Z
Updated: 2025-09-05T13:35:08.152Z
Reserved: 2024-01-03T16:43:30.196Z
Link: CVE-2024-21977

Updated: 2025-09-05T13:34:59.694Z

Status : Awaiting Analysis
Published: 2025-09-05T13:15:31.310
Modified: 2025-09-05T17:47:10.303
Link: CVE-2024-21977

No data.