Database/Control plane, storage & DevOps
AMD Graphics Driver - crafted pointer leading to arbitrary code execution: Improper input validation in the AMD
Impact
Improper input validation in the AMD graphics driver lets an attacker supply a crafted pointer and reach arbitrary code execution. At 8.8 this is the most severe of AMD's own graphics-driver advisories in the window: a pointer that crosses the driver boundary unvalidated means kernel-level execution from whatever context can issue the call.
Who can reach it
Local, via the graphics driver interface - reachable by a process holding the GPU device.
What to do
Update the AMD graphics driver package, then reload the driver or reboot. Confirm the fixed version is present in the ROCm/amdgpu build you actually deploy, since the packaged AMD driver and the mainline kernel driver move on different schedules.
References
Related entries
- Jenkins: Agent processes can read arbitrary controller files via ClassLoaderProxy#fetchJarCVE-2024-43044 · JenkinsHigh
- Digi ConnectPort LTS (before 1.4.12): An attacker who can reach the ConnectPort LTS's file-upload featureCVE-2024-50627 · Digi ConnectPort LTS (before 1.4.12)High
- Deep Sea Electronics DSE855 generator communications gateway: Six unauthenticated flaws in one device: two stack-basedCVE-2024-5948 · Deep Sea Electronics DSE855 generator communications gatewayHigh
- PostgreSQL: TOCTOU race in pg_dumpCVE-2024-7348 · PostgreSQLHigh
- Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone Controller: Malformed BACnetCVE-2025-0657 · Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone ControllerHigh
- Veeam Backup & Replication: Remote code execution reachable by any domain user on a domain-joined backup serverCVE-2025-23120 · Veeam Backup & ReplicationHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.