Database/AI/ML frameworks & serving
AMD graphics driver - dynamic power management (DPM) array index validation: An unvalidated array index in the driver's
CVSS 3.3CVE-2023-31306AI/ML frameworks & servingcurated
Impact
An unvalidated array index in the driver's dynamic power management functions produces an out-of-bounds access. DPM controls clocks and power states; on Instinct parts that is the machinery keeping accelerators inside their power and thermal envelope, so corruption here is worth more attention than the 3.3 score suggests even though the direct security impact is limited.
Who can reach it
Local, requires the ability to pass malformed arguments to DPM functions.
What to do
Update the AMD graphics driver and reload or reboot.
References
Related entries
- wandb SDK (`ArtifactManifestEntry.download`): Hash-handling weakness in artifact download integrityCVE-2026-15605 · wandb SDK (`ArtifactManifestEntry.download`)Low
- vLLM (prefix cache hash collisions): Crafted prompts collide hashesCVE-2025-25183 · vLLM (prefix cache hash collisions)Low
- vLLM (prefix cache): Prefix-cache timing side channel leaks other tenants' promptsCVE-2025-46570 · vLLM (prefix cache)Low
- vLLM: unvalidated bad_words token indices corrupt logits of other in-flight requestsCVE-2026-93989 · vLLM sampling parameters (bad_words token index validation)Low
- Langflow: authenticated user reaches eval() through component input options and runs code on the hostCVE-2026-101861 · Langflow schema.py (eval() on component input option values)Low
- mistral.rs: out-of-bounds read parsing GGUF token id metadata crashes the inference serverCVE-2026-75090 · mistral.rs GGUF tokenizer (convert_gguf_to_hf_tokenizer)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.