Home

Description

A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.

PUBLISHED Reserved 2024-05-23 | Published 2026-02-10 | Updated 2026-02-10 | Assigner AMD




MEDIUM: 4.6CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

Product status

Default status
affected

DragonRangeFL1PI 1.0.0.3h
unaffected

Default status
affected

ComboAM5PI 1.0.0.b
unaffected

ComboAM5PI 1.1.0.3d
unaffected

ComboAM5PI 1.2.0.3d
unaffected

Default status
affected

FireRangeFL1PI 1.0.0.0a
unaffected

Default status
affected

ComboAM5PI 1.1.0.3d
unaffected

ComboAM5PI 1.2.0.3d
unaffected

Default status
affected

ComboAM5PI 1.2.0.3d
unaffected

Default status
affected

EmbeddedAM5PI 1.0.0.4​
unaffected

References

www.amd.com/...es/product-security/bulletin/AMD-SB-4013.html

cve.org (CVE-2024-36311)

nvd.nist.gov (CVE-2024-36311)

Download JSON