Database/Control plane, storage & DevOps
AMD Graphics Driver - out-of-bounds write: Improper input validation lets a local attacker write out of bounds through
CVSS 6.9CVE-2025-48518Control plane, storage & DevOpscurated
Impact
Improper input validation lets a local attacker write out of bounds through the AMD graphics driver, costing integrity or availability. Out-of-bounds kernel writes reachable from a GPU device handle are the standard escape route out of a GPU container.
Who can reach it
Local, via the graphics driver interface - reachable from a tenant container with a GPU device node.
What to do
Update the AMD graphics driver package and reload the driver or reboot the node.
References
Related entries
- Terragrunt: malicious module manifest deletes files outside the module cache during cleanupCVE-2026-45099 · Terragrunt (module cache cleanup, .terragrunt-module-manifest path handling)Medium
- Inspektor Gadget: crafted ld.so.cache in a container stalls the container-start hook cluster-wideCVE-2026-53941 · Inspektor Gadget (uprobe ld.so.cache parser, pkg/uprobetracer)Medium
- Renovate: minimumReleaseAge is not applied to digest updates, so fresh dependency digests reach CI earlyCVE-2026-88884 · Renovate (minimumReleaseAge enforcement for digest updates)Medium
- Schneider Electric StruxureWare Data Center Expert before 7.4.0: Passwords held in cleartext in RAM on the DCIMCVE-2017-8371 · Schneider Electric StruxureWare Data Center Expert before 7.4.0Medium
- RPMB protocol message authentication subsystem in Intel TXE before 4.0.30 (replay-protected memory block)CVE-2020-12355 · RPMB protocol message authentication subsystem in Intel TXE before 4.0.30 (replay-protected memory block)Medium
- Replay Protected Memory Block (RPMB) protocol as specified for eMMC, UFS and ALL versions of NVMeCVE-2020-13799 · Replay Protected Memory Block (RPMB) protocol as specified for eMMC, UFS and ALL versions of NVMe - multi-vendor…Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.