Database/Control plane, storage & DevOps
AMD Graphics Driver - crafted pointer leading to arbitrary writes: A specially crafted pointer passed to the AMD
CVSS 8.4CVE-2024-36352Control plane, storage & DevOpscurated
Impact
A specially crafted pointer passed to the AMD graphics driver produces arbitrary writes or a crash. Arbitrary kernel writes from a GPU driver call is a privilege-escalation primitive available to anything with the device open - on a shared GPU node, that is the tenant.
Who can reach it
Local, via the graphics driver interface.
What to do
Update the AMD graphics driver and reload or reboot. Driver-level fix, no firmware step.
References
Related entries
- Dell CloudLink (command injection): Command injection giving a privileged user full control of the CloudLink systemCVE-2025-30479 · Dell CloudLink (command injection)High
- Dell CloudLink (console command injection): Command injection from the console giving shell accessCVE-2025-45379 · Dell CloudLink (console command injection)High
- Renovate (kustomize manager): chart names are injected into helm pull commands, running attacker shell commandsCVE-2026-76229 · Renovate (kustomize manager, helm pull)High
- Renovate (helmv3 manager): repository value from Chart.yaml is injected into helm registry login commandsCVE-2026-76232 · Renovate (helmv3 manager, helm registry login)High
- Vertiv Avocent UMG-4000 universal management gateway: Every command the UMG-4000's web interface runs executes as rootCVE-2019-9507 · Vertiv Avocent UMG-4000 universal management gatewayHigh
- Eaton Intelligent Power Manager (IPM) prior to 1.69 - dynamic eval: Unauthenticated eval injection: user-controlledCVE-2021-23277 · Eaton Intelligent Power Manager (IPM) prior to 1.69 - dynamic evalHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.