GPU VulnDB

Database/Control plane, storage & DevOps

AMD Radeon RGB tool - signature verification on files in the installation directory: The Radeon RGB tool does

CVE-2024-36334Control plane, storage & DevOpscurated

Impact

The Radeon RGB tool does not verify signatures on files placed in its installation directory, so a planted file runs with elevated privileges. A cosmetic utility that escalates to code execution - the reason it appears here is that vendor GPU tooling gets installed wholesale on GPU hosts without anyone asking what the LED control daemon is doing running as root.

Who can reach it

Local, requires write access to the tool's installation directory.

What to do

Update or, better, uninstall - RGB lighting control has no business on a datacenter GPU node. Removing unnecessary vendor tooling from the golden image is the durable fix and costs nothing at runtime. No reboot needed to uninstall.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.