CVE-2024-25742
CVE-2024-25742
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 May 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.9https://github.com/torvalds/linux/commit/e3ef461af35a8c74f2f4ce6616491ddb355a208fhttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e3ef461af35a8c74f2f4ce6616491ddb355a208fhttps://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html