Vulnerability in AMD Virtualization Technology Impacting JPEG Cores
CVE-2024-36323
8.8HIGH
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 15 May 2026
What is CVE-2024-36323?
The vulnerability arises from the improper isolation of the VCN-JPEG HW register space within AMD's virtualization technology. This flaw can allow a malicious Guest Virtual Machine (VM) or process to gain unauthorized access to the register space of JPEG cores assigned to a victim VM or process. Consequently, this may enable attackers to perform arbitrary read and write operations on the data of the affected VM or process, posing significant risks to data integrity and confidentiality.
Affected Version(s)
AMD Instinct™ MI300A ROCm 6.3
AMD Instinct™ MI300X ROCm 6.3
AMD Instinct™ MI308X ROC 6.3