AMD Secure Processor Type Confusion Vulnerability Allowing Memory Safety Violations
Vulnerability
A type confusion vulnerability has been identified in the AMD Secure Processor (ASP). This issue could allow an attacker to send a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA), leading to a memory safety violation. Such a violation could potentially result in a loss of confidentiality, integrity, or availability.
Impact
Exploitation of this vulnerability could lead to a memory safety violation, allowing for unauthorized access or modification of memory, which could be exploited to bypass security controls or cause unintended behavior in applications or the operating system.
Remediation
Users can update to the AMD graphics driver version 25.6.1 or later. For AMD Radeon PRO V710 series graphics cards, this update will be available on June 5, 2025. For AMD Ryzen Embedded 7000, 8000, and 9000 series processors, the update will be released on July 31, 2025.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
