CVE Vulnerabilities

CVE-2024-21977

Incomplete Cleanup

Published: Sep 05, 2025 | Modified: Sep 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Potential Mitigations

References