CVE-2026-0427

MEDIUM

AMD Instinct MI210/MI300X/MI325X >=GIM 8.2.0.K - Incomplete Cleanup of Shared Register Resources

Title source: llm
STIX 2.1

Description

Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from another Guest VM, potentially resulting in the loss of confidentiality, integrity, or availability.

Scores

CVSS v4 4.6
EPSS 0.0002
EPSS Percentile 4.5%
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-459
Status published
Products (4)
AMD/AMD Instinct™ MI210 GIM 8.2.0.K
AMD/AMD Instinct™ MI300X GIM 8.2.0.K
AMD/AMD Instinct™ MI325X GIM 8.2.0.K
AMD/AMD Radeon™ PRO V710 Contact your AMD Customer Engineering representative
Published May 15, 2026
Tracked Since May 15, 2026