CVE-2024-21949: Input Validation
Published Nov 12, 2024
·Updated
Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.
Affected Software
1 affected component
AMD Ryzen Ai Software<1.2
Event History
Nov 12, 2024
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21949?
The severity of CVE-2024-21949 is considered high due to its potential to cause a system crash.
2
How do I fix CVE-2024-21949?
To fix CVE-2024-21949, update the AMD Ryzen AI Software to version 1.2 or later.
3
What causes CVE-2024-21949?
CVE-2024-21949 is caused by improper validation of user input in the NPU driver.
4
What impact does CVE-2024-21949 have on my system?
CVE-2024-21949 could lead to unexpected behavior such as a system crash due to buffer size issues.
5
Is my system vulnerable to CVE-2024-21949?
If you are using a version of AMD Ryzen AI Software below 1.2, your system is vulnerable to CVE-2024-21949.