Type Confusion Vulnerability in AMD's Reliability, Availability, and Serviceability (RAS) Application
CVE-2023-31322

8.7HIGH

What is CVE-2023-31322?

A type confusion vulnerability exists within AMD's Reliability, Availability, and Serviceability (RAS) trusted application. This flaw allows an attacker to send a malformed argument, which could potentially lead to unauthorized read or write operations in shared memory. As a result, this vulnerability poses risks to the confidentiality, integrity, and availability of affected systems.

Affected Version(s)

-AMD Radeon™ PRO W7000 Series Graphics Products AMD Software: PRO Edition 24.Q2 (24.10.20)

AMD Radeon™ RX 7000 Series Graphics Products AMD Software: Adrenalin Edition 24.6.1 (24.10.21.01

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-31322 : Type Confusion Vulnerability in AMD's Reliability, Availability, and Serviceability (RAS) Application