CVE-2024-36311

A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Una condición de carrera de tipo Time-of-check time-of-use (TOCTOU) en el búfer de comunicaciones SMM podría permitir a un atacante privilegiado eludir la validación de entrada y realizar una lectura o escritura fuera de límites, lo que podría resultar en la pérdida de confidencialidad, integridad o disponibilidad.

10 Feb 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 20:16

Updated : 2026-04-15 00:35


NVD link : CVE-2024-36311

Mitre link : CVE-2024-36311

CVE.ORG link : CVE-2024-36311


JSON object : View

Products Affected

No product.

CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition