CVE-2024-21974: Input Validation
Published Nov 12, 2024
·Updated
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
Affected Software
1 affected component
AMD Ryzen Ai Software<1.2
Event History
Nov 12, 2024
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21974?
CVE-2024-21974 has been classified as a high severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-21974?
To fix CVE-2024-21974, update to the latest version of AMD Ryzen AI Software that is greater than 1.2.
3
What is the impact of CVE-2024-21974?
CVE-2024-21974 allows an attacker to exploit improper input validation in the NPU driver, which may lead to arbitrary code execution.
4
Which software is vulnerable to CVE-2024-21974?
CVE-2024-21974 affects AMD Ryzen AI Software versions less than 1.2.
5
Who discovered CVE-2024-21974?
CVE-2024-21974 was reported by AMD as part of their continuous security assessments.