Insufficient Boundary Validation in AMD Zynq UltraScale+ MPSoC and RFSoC Devices
CVE-2026-0461

7.5HIGH

What is CVE-2026-0461?

Insufficient boundary validation in the USB boot mode of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could enable unbounded Device Firmware Upgrade (DFU) requests, posing a risk of buffer overflow into the FSBL memory. This vulnerability may lead to unauthorized execution of code during the boot process, putting the confidentiality, integrity, and availability of devices at risk.

Affected Version(s)

Kria SOMs 2026.1

Zynq™ UltraScale+ MPSoCs 2026.1

Zynq™ UltraScale+ RFSoCs 2026.1

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.