CVE-2024-36331 describes an improper initialization vulnerability in CPU cache memory that could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory, leading to a loss of data integrity. This vulnerability has a low CVSS score of 3.2, indicating a low severity, and requires high privileges and local access to exploit, with no impact on confidentiality or availability. There is currently no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and no community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AMD | AMD EPYC™ 9004 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ Embedded 9004 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | EPYC™ Embedded 9004 Series Processors | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026