CVE-2024-36310
Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or integrity.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-124
- Published
- 2026-02-10
- Last modified
- 2026-03-13
Affected products
- AMD AMD EPYC™ 9004 Series Processors
- AMD AMD EPYC™ 9005 Series Processors
- AMD AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 9000HX Series Mobile Processors
- AMD AMD Ryzen™ AI Max 300 Series Processors
- AMD AMD Ryzen™ AI 300 Series Processors
Weakness type
Related vulnerabilities
- CVE-2026-40013 — An attacker that has valid credentials can submit a Sieve script containing an extreme numeric...
- CVE-2026-73075 — Vim: Out-of-bounds Access in Popup Opacity Handling
- CVE-2026-71969 — OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
- CVE-2026-16439 — Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow
- CVE-2026-26199 — Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
- CVE-2026-44631 — Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
- CVE-2024-36343 — Improper input validation in the System Management Mode (SMM) communications buffer could allow a...
- CVE-2026-5089 — YAML::Syck versions before 1.38 for Perl has an out-of-bounds read