Memory Buffer Vulnerability in AMD Secure Processor
CVE-2023-31317

8.8HIGH

What is CVE-2023-31317?

An improper restriction in the AMD Secure Processor (ASP) allows an attacker to manipulate protected memory areas. This vulnerability can enable unauthorized reading or writing of memory, which may lead to arbitrary code execution, posing substantial risks to system integrity and confidentiality.

Affected Version(s)

AMD Instinct™ MI210 ROCm 7.0

AMD Instinct™ MI250 ROCm 7.0

AMD Radeon™ PRO W6000 Series Graphics Products AMD Software: PRO Edition 25.Q3.1 (25.10.32)

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.