CVE-2024-36319: AMD Instinct MI300A

Medium severity, CVSS 6.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.

Affected products

  • AMD AMD Instinct MI300A
  • AMD AMD Instinct MI300X
  • AMD AMD Instinct MI308X
  • AMD AMD Instinct MI325X
  • AMD AMD Radeon Pro v710
  • AMD AMD Radeon Pro w7000 Series Graphics Products
  • AMD AMD Radeon Rx 7000 Series Graphics Products
  • AMD AMD Ryzen 7040 Series Mobile Processors With Radeon Graphics; AMD Ryzen 8040 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 8000 Series Desktop Processors
  • AMD AMD Ryzen Ai 300 Series Processors
  • AMD AMD Ryzen Ai Max Series Processors
  • AMD AMD Ryzen Embedded 7000 Series Processors
  • AMD AMD Ryzen Embedded 8000 Series Processors
  • AMD AMD Ryzen Embedded 9000 Series Processors

Published 2026-02-12. Last modified 2026-06-17.