CVE-2024-36311

MEDIUM

SMM - Memory Corruption

Title source: llm
STIX 2.1

Description

A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.

Scores

CVSS v4 4.6
EPSS 0.0001
EPSS Percentile 3.3%
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (9)
AMD/AMD Ryzen™ 7000 Series Desktop Processors ComboAM5PI 1.0.0.b
AMD/AMD Ryzen™ 7000 Series Desktop Processors ComboAM5PI 1.1.0.3d
AMD/AMD Ryzen™ 7000 Series Desktop Processors ComboAM5PI 1.2.0.3d
AMD/AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics DragonRangeFL1PI 1.0.0.3h
AMD/AMD Ryzen™ 8000 Series Desktop Processors ComboAM5PI 1.1.0.3d
AMD/AMD Ryzen™ 8000 Series Desktop Processors ComboAM5PI 1.2.0.3d
AMD/AMD Ryzen™ 9000 Series Desktop Processors ComboAM5PI 1.2.0.3d
AMD/AMD Ryzen™ 9000HX Series Mobile Processors FireRangeFL1PI 1.0.0.0a
AMD/AMD Ryzen™ Embedded 7000 Series Processors EmbeddedAM5PI 1.0.0.4​
Published Feb 10, 2026
Tracked Since Feb 18, 2026