Input validation error in AMD Instinct MI300X - CVE-2024-21935
Published: February 24, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input in Satellite Management Controller (SMC). A remote attacker can pass specially crafted input to the application and remove files from the local root directory, resulting in data corruption.
Affected software
ThinkSystem SR685a V3
AMD Graphics Processing Unit (GPU) Adapter Firmware
How to mitigate CVE-2024-21935
AMD Graphics Processing Unit (GPU) Adapter Firmware - update to BKC 24.12.10