CVE-2023-31317

HIGH

Amd Radeon™ RX 6000 Series Graphics Products - Improper Restriction of Operations within the Bounds of a Memory Buffer

Title source: rule
STIX 2.1

Description

Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution.

Scores

CVSS v4 8.8
EPSS 0.0002
EPSS Percentile 4.3%
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119
Status published
Products (6)
AMD/AMD Instinct™ MI210 ROCm 7.0
AMD/AMD Instinct™ MI250 ROCm 7.0
AMD/AMD Radeon™ PRO W6000 Series Graphics Products AMD Software: PRO Edition 25.Q3.1 (25.10.32)
AMD/AMD Radeon™ PRO W7000 Series Graphics Products AMD Software: PRO Edition 25.Q3.1 (25.10.32)
AMD/AMD Radeon™ RX 6000 Series Graphics Products AMD Software: Adrenalin Edition 25.11.1 (25.10.33.03)
AMD/AMD Radeon™ RX 7000 Series Graphics Products AMD Software: Adrenalin Edition 25.11.1 (25.20.29.01)
Published May 15, 2026
Tracked Since May 15, 2026