CVE-2024-21975: Input Validation
Published Nov 12, 2024
·Updated
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
Affected Software
1 affected component
AMD Ryzen Ai Software<1.2
Event History
Nov 12, 2024
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21975?
CVE-2024-21975 is considered a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-21975?
To fix CVE-2024-21975, update the affected AMD Ryzen AI Software to version 1.2 or later.
3
What can happen if I don't address CVE-2024-21975?
If left unaddressed, CVE-2024-21975 can allow attackers to execute arbitrary code on affected systems.
4
What type of vulnerability is CVE-2024-21975?
CVE-2024-21975 is categorized as an improper input validation vulnerability.
5
Which software is affected by CVE-2024-21975?
CVE-2024-21975 affects AMD Ryzen AI Software versions prior to 1.2.