Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amd
Amd epyc 7003 Series Processors Amd epyc 9004 Series Processors |
|
| Vendors & Products |
Amd
Amd epyc 7003 Series Processors Amd epyc 9004 Series Processors |
Wed, 10 Jun 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | DIMM SPD Metadata Validation Error Allows Guest Memory Overwrite |
Wed, 10 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity. | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMD
Published:
Updated: 2026-06-10T21:54:19.444Z
Reserved: 2024-01-03T16:43:21.322Z
Link: CVE-2024-21944
No data.
Status : Received
Published: 2026-06-10T23:16:44.950
Modified: 2026-06-10T23:16:44.950
Link: CVE-2024-21944
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:30:11Z
Weaknesses