Aller au contenu

Fiche vulnérabilité

CVE-2023-31324 : faille élevée amd rocm (CVSS 7.8)

Description

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
11 févr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • amd rocm
  • amd radeon software
  • amd radeon pro vii firmware
  • amd radeon vii firmware

Références

Rechercher une autre vulnérabilité dans la base CVE