HIGH🇵🇱 Wersja polska

CVE-2023-31324

CVSS 7.1v4.0pub. 2026-02-11upd. 2026-03-05

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.

CVSS Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Amd Instinct Mi210

    HW
    Amd
    all versions
  • Amd Instinct Mi250

    HW
    Amd
    all versions
  • Amd Instinct Mi300a

    HW
    Amd
    all versions
  • Amd Instinct Mi300x

    HW
    Amd
    all versions
  • Amd Radeon Pro Vii

    HW
    Amd
    all versions
  • Amd Radeon Pro Vii Firmware

    OS
    Amd
    all versions
  • Amd Radeon Pro W5500

    HW
    Amd
    all versions
  • Amd Radeon Pro W5500x

    HW
    Amd
    all versions
  • Amd Radeon Pro W5700

    HW
    Amd
    all versions
  • Amd Radeon Pro W5700x

    HW
    Amd
    all versions
  • Amd Radeon Rx 5300

    HW
    Amd
    all versions
  • Amd Radeon Rx 5300m

    HW
    Amd
    all versions
  • Amd Radeon Rx 5300 Xt

    HW
    Amd
    all versions
  • Amd Radeon Rx 5500

    HW
    Amd
    all versions
  • Amd Radeon Rx 5500m

    HW
    Amd
    all versions
  • Amd Radeon Rx 5500 Xt

    HW
    Amd
    all versions
  • Amd Radeon Rx 5600

    HW
    Amd
    all versions
  • Amd Radeon Rx 5600m

    HW
    Amd
    all versions
  • Amd Radeon Rx 5600 Xt

    HW
    Amd
    all versions
  • Amd Radeon Rx 5700

    HW
    Amd
    all versions
  • Amd Radeon Rx 5700m

    HW
    Amd
    all versions
  • Amd Radeon Rx 5700 Xt

    HW
    Amd
    all versions
  • Amd Radeon Software

    APP
    Amd
    < 24.6.1< 25.q2
  • Amd Radeon Vii

    HW
    Amd
    all versions
  • Amd Radeon Vii Firmware

    OS
    Amd
    all versions
  • Amd Rocm

    APP
    Amd
    < 6.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Race Condition
CWE
References

Related vulnerabilities

CVE-2023-20586CRITICAL9.8PL ✓same product

Privilege escalation w AMD Radeon Software Crimson ReLive Edition

CVE-2024-36333HIGH7.0same product

A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalati...

CVE-2023-20548HIGH7.1same product

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker ...

CVE-2024-21937HIGH7.3same product

Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve pri...

CVE-2023-31320HIGH7.5same product

Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the dis...