CVE-2024-36323: AMD Instinct MI300A

High severity, CVSS 8.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perform unauthorized access to the register space of the JPEG cores assigned a victim VM/process, potentially gaining arbitrary read/write access to the victim VM/process data.

Affected products

  • AMD AMD Instinct MI300A
  • AMD AMD Instinct MI300X
  • AMD AMD Instinct MI308X
  • AMD AMD Instinct MI325X
  • AMD AMD Radeon Pro w7000 Series Graphics Products
  • AMD AMD Radeon Rx 7000 Series Graphics Products

Published 2026-05-15. Last modified 2026-06-17.