SARA / Free Tools / CVE / CVE-2024-36342

CVE-2024-36342 — Improper input validation in the GPU driver could allow an attacker to exploit a

Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in arbitrary code execution.

CVSS
8.8 HIGH
EPSS
3.00% (top 92.00%)
CWE
CWE-1285
Published
2025-09-06T17:42:00.232Z
Last modified
2026-02-26T17:49:09.671Z
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

01What is this vulnerability?

Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in arbitrary code execution.

02Affected products

VendorProductVersions
AMDAMD Ryzen™ 4000 Series Mobile Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 7035 Series Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 7040 Series Mobile Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 7020 Series Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 7045 Series Mobile Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 7000 Series Desktop ProcessorsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 7030 Series Mobile Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ AI 300 Series ProcessorsRadeon Software for Linux 25.10.x
AMDAMD Athlon™ 3000 Series Desktop Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 8000 Series Desktop ProcessorsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 9000 Series Desktop ProcessorsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 5000 Series Mobile Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 5000 Series Mobile Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 4000 Series Desktop ProcessorsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 5000 Series Desktop Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 8040 Series Mobile Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 3000 Series Mobile Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ 6000 Series Processors with Radeon™ GraphicsRadeon Software for Linux 25.10.x
AMDAMD Ryzen™ Embedded R2000 Series Processorsamd_chipset_software_7.06.02.123.exe , PSP driver version: 5.39.0.0
AMDAMD Ryzen™ Embedded V2000 Series Processorsamd_chipset_software_7.06.02.123.exe , PSP driver version: 5.39.0.0
AMDAMD Ryzen™ Embedded 8000 Seriesamd_chipset_software_7.06.02.123.exe , PSP driver version: 5.39.0.0
AMDAMD Ryzen™ Embedded 7000 Series Processorsamd_chipset_software_7.06.02.123.exe , PSP driver version: 5.39.0.0
AMDAMD Radeon™ RX 5000 Series Graphics ProductsRadeon Software for Linux 25.10.1
AMDAMD Radeon™ PRO W5000 Series Graphics ProductsRadeon Software for Linux 25.10.1
AMDAMD Radeon™ RX 6000 Series Graphics ProductsRadeon Software for Linux 25.10.1
AMDAMD Radeon™ PRO W6000 Series Graphics ProductsRadeon Software for Linux 25.10.1
AMDAMD Radeon™ RX 7000 Series Graphics ProductsRadeon Software for Linux 25.10.1
AMDAMD Radeon™ PRO W7000 Series Graphics ProductsRadeon Software for Linux 25.10.1
AMDAMD Radeon™ RX 9000 Series Graphics ProductsRadeon Software for Linux 25.10.1
AMDAMD Radeon™ RX Vega Series Graphics CardsRadeon Software for Linux 25.10.1
AMDAMD Radeon™ PRO VIIRadeon Software for Linux 25.10.1
AMDAMD Instinct™ MI210ROCm 6.4
AMDAMD Instinct™ MI250ROCm 6.4
AMDAMD Instinct™ MI300AROCm 6.4
AMDAMD Instinct™ MI300XROCm 6.4
AMDAMD Instinct™ MI308XROCm 6.4
AMDAMD Instinct™ MI325XROCm 6.4
AMDAMD Radeon™ PRO V520 Graphics ProductsContact your AMD Customer Engineering representative
AMDAMD Radeon™ PRO V620 Graphics ProductsContact your AMD Customer Engineering representative
AMDAMD Radeon™ PRO V710 Graphics ProductsContact your AMD Customer Engineering representative

03Active exploitation status

Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.

04Recommended remediation

05Technical details

For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.

06Detection signatures

Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:

Open in Sigma generator →

07Related CVEs

No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.

08Timeline

09References

Want this in your SOAR or SIEM?
SARA's API returns EPSS, CVSS, KEV, and an analyst-grade summary in one call.
Read the API reference →