https://seclists.org/oss-sec/2025/q1/178: Xen Security Notice 2 (CVE-2024-35347) AMD CPU Microcode SignatuVerification Vulnerability
Published Mar 6, 2025
·Updated
Affected Software
2 affected components
Xen Project Xen
Linux Linux kernel
Frequently Asked Questions
1
What is the severity of CVE-2024-35347?
CVE-2024-35347 has been classified as a significant vulnerability due to potential exploitation affecting AMD CPU microcode verification.
2
How do I fix CVE-2024-35347?
To mitigate CVE-2024-35347, users should update their Xen Project software and apply any related patches provided by their distributions.
3
What systems are affected by CVE-2024-35347?
CVE-2024-35347 primarily affects systems using Xen Project hypervisors on AMD CPUs.
4
What is the primary risk associated with CVE-2024-35347?
The primary risk of CVE-2024-35347 is the potential for unauthorized manipulation of microcode, leading to escalated privileges or system instability.
5
How can I determine if my system is vulnerable to CVE-2024-35347?
To determine vulnerability to CVE-2024-35347, check if your current Xen Project version and CPU microcode match the specifications outlined in the security advisory.