7.7

CVE-2026-43598

Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a compromised peer rank or network-adjacent attacker to dereference an attacker-controlled pointer, potentially resulting in remote code execution.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAMD
≫
Produkt AMD Instinct™ MI210
Default Statusaffected
Version ROCm 7.14
Status unaffected
HerstellerAMD
≫
Produkt AMD Instinct™ MI250
Default Statusaffected
Version ROCm 7.14
Status unaffected
HerstellerAMD
≫
Produkt AMD Instinct™ MI300A
Default Statusaffected
Version ROCm 7.14
Status unaffected
HerstellerAMD
≫
Produkt AMD Instinct™ MI300X
Default Statusaffected
Version ROCm 7.14
Status unaffected
HerstellerAMD
≫
Produkt AMD Instinct™ MI325X
Default Statusaffected
Version ROCm 7.14
Status unaffected
HerstellerAMD
≫
Produkt AMD Instinct™ MI350X
Default Statusaffected
Version ROCm 7.14
Status unaffected
HerstellerAMD
≫
Produkt AMD Instinct™ MI355X
Default Statusaffected
Version ROCm 7.14
Status unaffected
HerstellerAMD
≫
Produkt AMD Instinct™ MI308X
Default Statusaffected
Version ROCm 7.14
Status unaffected
HerstellerAMD
≫
Produkt AMD Instinct™ MI250X
Default Statusaffected
Version ROCm 7.14
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.377
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
AMD 7.7 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-822 Untrusted Pointer Dereference

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6033.html