Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited section of the Top of Memory Segment (TSEG) memory region, potentially resulting in loss of confidentiality or integrity.
History

Wed, 20 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 May 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd epyc 4004
Amd epyc 4005
Amd ryzen 6000 Series Processors With Radeon Graphics
Amd ryzen 7000 Series Desktop Processors
Amd ryzen 7040 Series Mobile Processors With Radeon Graphics
Amd ryzen 7045 Series Mobile Processors With Radeon Graphics
Amd ryzen 8000 Series Desktop Processors
Amd ryzen 9000 Series Desktop Processors
Amd ryzen 9000hx Series Mobile Processors
Amd ryzen Ai 300 Series Processors
Amd ryzen Al Max+
Amd ryzen Embedded 7000 Series Processors
Amd ryzen Embedded 8000 Series Processors
Amd ryzen Embedded 9000 Series Processors
Amd ryzen Embedded V3000 Series Processors
Amd ryzen Threadripper 7000 Processors
Amd ryzen Threadripper Pro 7000 Wx-series Processors
Vendors & Products Amd
Amd epyc 4004
Amd epyc 4005
Amd ryzen 6000 Series Processors With Radeon Graphics
Amd ryzen 7000 Series Desktop Processors
Amd ryzen 7040 Series Mobile Processors With Radeon Graphics
Amd ryzen 7045 Series Mobile Processors With Radeon Graphics
Amd ryzen 8000 Series Desktop Processors
Amd ryzen 9000 Series Desktop Processors
Amd ryzen 9000hx Series Mobile Processors
Amd ryzen Ai 300 Series Processors
Amd ryzen Al Max+
Amd ryzen Embedded 7000 Series Processors
Amd ryzen Embedded 8000 Series Processors
Amd ryzen Embedded 9000 Series Processors
Amd ryzen Embedded V3000 Series Processors
Amd ryzen Threadripper 7000 Processors
Amd ryzen Threadripper Pro 7000 Wx-series Processors

Tue, 19 May 2026 23:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Access in AMD System Management Mode Communication Buffer

Tue, 19 May 2026 21:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited section of the Top of Memory Segment (TSEG) memory region, potentially resulting in loss of confidentiality or integrity.
Weaknesses CWE-124
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-05-20T13:46:23.737Z

Reserved: 2024-05-23T19:44:47.200Z

Link: CVE-2024-36343

cve-icon Vulnrichment

Updated: 2026-05-20T13:46:18.360Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-19T22:16:35.420

Modified: 2026-05-20T14:04:24.967

Link: CVE-2024-36343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-20T10:38:58Z