CVE-2026-0481
- EPSS 0.2%
- Veröffentlicht 15.05.2026 03:04:56
- Zuletzt bearbeitet 15.05.2026 14:10:17
Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability
- EPSS 0.01%
- Veröffentlicht 15.05.2026 02:59:46
- Zuletzt bearbeitet 15.05.2026 14:10:17
A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an attacker to trigger a heap-based buffer overflow, poten...
CVE-2023-31317
- EPSS 0.02%
- Veröffentlicht 15.05.2026 02:47:12
- Zuletzt bearbeitet 15.05.2026 14:10:17
Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution.
CVE-2025-54517
- EPSS 0.04%
- Veröffentlicht 15.05.2026 02:44:54
- Zuletzt bearbeitet 15.05.2026 14:10:17
Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution.
CVE-2025-66660
- EPSS 0.03%
- Veröffentlicht 15.05.2026 02:42:33
- Zuletzt bearbeitet 15.05.2026 14:10:17
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cause incorrect shared memory mapping, potentially resulting in unexpected behavior.
CVE-2025-66664
- EPSS 0.01%
- Veröffentlicht 15.05.2026 02:41:56
- Zuletzt bearbeitet 15.05.2026 14:10:17
Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory content...
CVE-2023-31323
- EPSS 0.02%
- Veröffentlicht 12.02.2026 17:45:12
- Zuletzt bearbeitet 15.04.2026 00:35:42
Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of confidentia...
CVE-2023-31313
- EPSS 0.02%
- Veröffentlicht 12.02.2026 14:16:53
- Zuletzt bearbeitet 15.04.2026 00:35:42
An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.
CVE-2023-20548
- EPSS 0.01%
- Veröffentlicht 11.02.2026 14:35:16
- Zuletzt bearbeitet 05.03.2026 17:44:49
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.
CVE-2023-31324
- EPSS 0.01%
- Veröffentlicht 11.02.2026 14:34:54
- Zuletzt bearbeitet 05.03.2026 17:45:32
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confid...