Arbitrary Code Execution Vulnerability in AMD Power Management Firmware
CVE-2023-31313
7.2HIGH
Key Information:
- Vendor
Amd
- Vendor
- CVE Published:
- 12 February 2026
What is CVE-2023-31313?
An unexpected proxy or intermediary in the AMD power management firmware may allow an attacker with privileges to craft and send malformed messages to the system management unit (SMU). This flaw potentially exposes the system to arbitrary code execution, posing significant risks to system integrity and confidentiality. Users are encouraged to review the security advisory for further details on mitigating actions.
Affected Version(s)
AMD Instinct™ MI210 ROCm 6.4.2
AMD Instinct™ MI250 ROCm 6.4.2