Insufficient Boundary Validation in AMD Zynq UltraScale+ MPSoC and RFSoC Devices
CVE-2026-0461
7.5HIGH
Key Information:
- Vendor
Amd
- Vendor
- CVE Published:
- 5 October 2026
What is CVE-2026-0461?
Insufficient boundary validation in the USB boot mode of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could enable unbounded Device Firmware Upgrade (DFU) requests, posing a risk of buffer overflow into the FSBL memory. This vulnerability may lead to unauthorized execution of code during the boot process, putting the confidentiality, integrity, and availability of devices at risk.
Affected Version(s)
Kria SOMs 2026.1
Zynq™ UltraScale+ MPSoCs 2026.1
Zynq™ UltraScale+ RFSoCs 2026.1