CVE-2024-21977 Details
Description
Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests.
A vulnerability exists in certain AMD processors due to incomplete cleanup after loading CPU microcode patches. This flaw may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially compromising the integrity of SEV-SNP (Secure Encrypted Virtualization - Secure Nested Paging) guests. The issue affects several AMD EPYC and Ryzen processor series.
Users are advised to update to the latest Platform Initialization (PI) firmware version. Specific update instructions can be obtained from the original equipment manufacturer (OEM).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 5, 2025CISA-ADP
Assessed Sep 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3014.html | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4012.html | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-5007.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-459 | Incomplete Cleanup | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AMD EPYC 4004 | All versions |
CPE
Remediation
| |
| AMD EPYC 7001 | All versions |
CPE
Remediation
| |
| AMD EPYC 7002 | All versions |
CPE
Remediation
| |
| AMD EPYC 7003 | All versions |
CPE
Remediation
| |
| AMD EPYC 8004 | All versions |
CPE
Remediation
| |
| AMD EPYC 9004 | All versions |
CPE
Remediation
| |
| AMD EPYC 9005 | All versions |
CPE
Remediation
| |
| AMD Athlon 3000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 5000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 7030 | All versions |
CPE
Remediation
| |
| AMD Ryzen 6000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 7020 | All versions |
CPE
Remediation
| |
| AMD Ryzen 7040 | All versions |
CPE
Remediation
| |
| AMD Ryzen 8040 | All versions |
CPE
Remediation
| |
| AMD Ryzen 7000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper 3000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper PRO 3000WX | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper PRO 5000WX | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper 7000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Threadripper PRO 7000WX | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 3000 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 7002 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 7003 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 9005 | All versions |
CPE
Remediation
| |
| AMD EPYC Embedded 900 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 5000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 7000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 8000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded R1000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded R2000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded V1000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded V2000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded V3000 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2025 | New CVE Received | [email protected] |
Volerion