{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/cloudlinux7els/vex/2024/cve-2024-45332-els_os-cloudlinux7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-12T22:12:17Z",
      "generator": {
        "date": "2026-06-12T22:12:17Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2024-45332-ELS_OS-CLOUDLINUX7ELS",
      "initial_release_date": "2024-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2024-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-12T22:12:17Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2024-45332"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "CloudLinux 7",
                "product": {
                  "name": "CloudLinux 7",
                  "product_id": "CloudLinux-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:cloudlinux:cloudlinux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "CloudLinux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.21.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.21.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.21.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/microcode_ctl@2.1-73.21.el7_9?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.25.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.25.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.25.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/microcode_ctl@2.1-73.25.el7_9?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.22.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.22.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.22.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/microcode_ctl@2.1-73.22.el7_9?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.26.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.26.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/microcode_ctl@2.1-73.26.el7_9?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.21.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.21.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.21.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/microcode_ctl@2.1-73.21.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/microcode_ctl@2.1-73.25.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.22.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.22.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.22.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/microcode_ctl@2.1-73.22.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/microcode_ctl@2.1-73.26.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.21.el7_9.tuxcare.els1.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:microcode_ctl-2:2.1-73.21.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.21.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.21.el7_9.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:microcode_ctl-2:2.1-73.21.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.21.el7_9.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.25.el7_9.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:microcode_ctl-2:2.1-73.25.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.25.el7_9.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.22.el7_9.tuxcare.els1.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:microcode_ctl-2:2.1-73.22.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.22.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.22.el7_9.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:microcode_ctl-2:2.1-73.22.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.22.el7_9.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.26.el7_9.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:microcode_ctl-2:2.1-73.26.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.26.el7_9.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-45332",
      "cwe": {
        "id": "CWE-1423",
        "name": "Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution"
      },
      "notes": [
        {
          "category": "description",
          "text": "Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "CloudLinux-7:microcode_ctl-2:2.1-73.21.el7_9.tuxcare.els1.x86_64",
          "CloudLinux-7:microcode_ctl-2:2.1-73.21.el7_9.x86_64",
          "CloudLinux-7:microcode_ctl-2:2.1-73.22.el7_9.tuxcare.els1.x86_64",
          "CloudLinux-7:microcode_ctl-2:2.1-73.22.el7_9.x86_64",
          "CloudLinux-7:microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
          "CloudLinux-7:microcode_ctl-2:2.1-73.25.el7_9.x86_64",
          "CloudLinux-7:microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
          "CloudLinux-7:microcode_ctl-2:2.1-73.26.el7_9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-45332"
        }
      ],
      "release_date": "2025-05-13T21:03:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-06-12T13:03:59.134949Z",
          "details": "This is a local-only, high‑complexity speculative‑execution side channel that requires an authenticated attacker to run code co‑resident on the same CPU core to influence/observe indirect branch predictor state; it offers no remote path. It affects only certain Intel processors and impacts confidentiality without any integrity or availability effect, so it cannot modify systems or cause outages. Given the need for precise co‑residency and timing, practical exploitability in centrally managed server/VM environments is low, making this reasonable to deprioritize relative to remotely exploitable or privilege‑escalation issues.",
          "product_ids": [
            "CloudLinux-7:microcode_ctl-2:2.1-73.21.el7_9.tuxcare.els1.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.21.el7_9.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.22.el7_9.tuxcare.els1.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.22.el7_9.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.25.el7_9.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.26.el7_9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CloudLinux-7:microcode_ctl-2:2.1-73.21.el7_9.tuxcare.els1.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.21.el7_9.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.22.el7_9.tuxcare.els1.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.22.el7_9.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.25.el7_9.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
            "CloudLinux-7:microcode_ctl-2:2.1-73.26.el7_9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}