CVE-2026-0481
- EPSS 0.2%
- Veröffentlicht 15.05.2026 03:04:56
- Zuletzt bearbeitet 15.05.2026 14:10:17
Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability
- EPSS 0.01%
- Veröffentlicht 15.05.2026 02:59:46
- Zuletzt bearbeitet 15.05.2026 14:10:17
A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an attacker to trigger a heap-based buffer overflow, poten...
CVE-2026-0427
- EPSS 0.01%
- Veröffentlicht 15.05.2026 02:51:22
- Zuletzt bearbeitet 15.05.2026 14:10:17
Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from another Guest VM, potentially resulting in the loss of confidentiality, int...
CVE-2023-31317
- EPSS 0.02%
- Veröffentlicht 15.05.2026 02:47:12
- Zuletzt bearbeitet 15.05.2026 14:10:17
Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution.
CVE-2025-54517
- EPSS 0.04%
- Veröffentlicht 15.05.2026 02:44:54
- Zuletzt bearbeitet 15.05.2026 14:10:17
Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution.
CVE-2025-66660
- EPSS 0.03%
- Veröffentlicht 15.05.2026 02:42:33
- Zuletzt bearbeitet 15.05.2026 14:10:17
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cause incorrect shared memory mapping, potentially resulting in unexpected behavior.
CVE-2025-66664
- EPSS 0.01%
- Veröffentlicht 15.05.2026 02:41:56
- Zuletzt bearbeitet 15.05.2026 14:10:17
Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory content...
CVE-2023-31323
- EPSS 0.02%
- Veröffentlicht 12.02.2026 17:45:12
- Zuletzt bearbeitet 15.04.2026 00:35:42
Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of confidentia...
CVE-2023-31313
- EPSS 0.02%
- Veröffentlicht 12.02.2026 14:16:53
- Zuletzt bearbeitet 15.04.2026 00:35:42
An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.
CVE-2023-20548
- EPSS 0.01%
- Veröffentlicht 11.02.2026 14:35:16
- Zuletzt bearbeitet 05.03.2026 17:44:49
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.