CVE-2024-21944: AMD Epyc 7003 Series Processors

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.

Affected products

  • AMD AMD Epyc 7003 Series Processors
  • AMD AMD Epyc 9004 Series Processor

Published 2026-06-10. Last modified 2026-07-23.