CVE-2024-36343
Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited section of the Top of Memory Segment (TSEG) memory region, potentially resulting in loss of confidentiality or integrity.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.19%
- CWE
- CWE-124
- Published
- 2026-05-19
- Last modified
- 2026-05-20
Affected products
- AMD AMD EPYC™ 4004
- AMD AMD EPYC™ 4005
- AMD AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 7000 Series Desktop Processors
- AMD AMD Ryzen™ 7000 Series Desktop Processors
- AMD AMD Ryzen™ 7000 Series Desktop Processors
Weakness type
Related vulnerabilities
- CVE-2026-40013 — An attacker that has valid credentials can submit a Sieve script containing an extreme numeric...
- CVE-2026-73075 — Vim: Out-of-bounds Access in Popup Opacity Handling
- CVE-2026-71969 — OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
- CVE-2026-16439 — Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow
- CVE-2026-26199 — Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
- CVE-2026-44631 — Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
- CVE-2026-5089 — YAML::Syck versions before 1.38 for Perl has an out-of-bounds read
- CVE-2026-41499 — Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()