Race Condition Vulnerability in AMD SMM Communications Buffer
CVE-2024-36311
4.6MEDIUM
Key Information:
What is CVE-2024-36311?
A time-of-check time-of-use (TOCTOU) race condition found in the SMM communications buffer of AMD products allows a privileged attacker to exploit input validation mechanisms. This flaw can facilitate out-of-bounds reads or writes, resulting in potential breaches of confidentiality, integrity, or availability. Remediation measures are crucial to mitigate the risk associated with this vulnerability.
Affected Version(s)
AMD Ryzen™ 7000 Series Desktop Processors ComboAM5PI 1.0.0.b
AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics DragonRangeFL1PI 1.0.0.3h
AMD Ryzen™ 8000 Series Desktop Processors ComboAM5PI 1.1.0.3d