Vulnerability in Video Decoder Engine Firmware from AMD
CVE-2024-36319
6.3MEDIUM
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 12 February 2026
What is CVE-2024-36319?
A vulnerability exists in AMD's Video Decoder Engine Firmware that stems from debug code being unnecessarily active. This flaw enables an attacker to send crafted commands, which could manipulate hardware registers. The potential consequences of this vulnerability include unauthorized access to sensitive information, disruption of system operations, and compromises to both system integrity and availability. Users of affected firmware versions should take immediate action to mitigate the risk associated with this exploitation.
Affected Version(s)
AMD Instinct™ MI300A ROCm 6.2.4
AMD Instinct™ MI300X ROCm 6.2.4
AMD Instinct™ MI308X ROCm 6.2.4