Race Condition Vulnerability in MxGPU-Virtualization Driver by AMD
CVE-2025-52532

2LOW

What is CVE-2025-52532?

A race condition in the MxGPU-Virtualization driver’s ioctl interface arises from unsynchronized concurrent access to the global variable amdgv_cmd. This vulnerability could enable an attacker to exploit the system through a carefully crafted attack, triggering a heap-based buffer overflow. Such exploitation may ultimately lead to denial-of-service scenarios within the affected system's environment, compromising its stability and security.

Affected Version(s)

AMD Instinct™ MI210 GIM Driver 8.4

AMD Instinct™ MI250 GIM Driver 8.4

AMD Instinct™ MI300A GIM Driver 8.4

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported through AMD Bug Bounty Program
.