AMD OverDrive SMM OOB Read via Improper Input Validation
CVE-2024-36345 Published on May 15, 2026

Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality.

NVD

Weakness Type

Insufficient Protections on the Volatile Memory Containing Boot Code

The protections on the product's non-volatile memory containing boot code are insufficient to prevent the bypassing of secure boot or the execution of an untrusted, boot code chosen by an adversary.


Affected Versions

AMD EPYC™ 4004: AMD EPYC™ 4005: AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics: AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics: AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics: AMD Ryzen™ 7000 Series Desktop Processors: AMD Ryzen™ 9000HX Series Mobile Processors: AMD Ryzen™ AI MAX: AMD Ryzen™ AI 300 Series Processors: AMD Ryzen™ Threadripper™ 7000 Processors: AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors: AMD Ryzen™ 8000 Series Desktop Processors: AMD Ryzen™ 9000 Series Desktop Processors: AMD Ryzen™ 9000 Series Desktop Processors: AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics: AMD Ryzen™ Embedded 8000 Series Processors: AMD Ryzen™ Embedded V3000 Series Processors: AMD Ryzen™ Embedded 7000 Series Processors: AMD Ryzen™ Embedded 9000 Series Processors: