Executive brief
A flaw in AMD's System Management Unit (SMU) firmware allows a malicious virtual function to invoke certain command handlers improperly, triggering an out-of-bounds memory read. This can cause the SMU to crash or become unresponsive, disrupting system stability and availability.
Technical details
This vulnerability is an out-of-bounds memory read in AMD System Management Unit (SMU) command handlers. A malicious virtual function can invoke certain SMU command handlers in an unsafe manner, triggering memory access beyond intended bounds. The attack requires the ability to create or control virtual functions, which typically requires local or administrative access. Successful exploitation results in denial of service through SMU crash or hang. The vulnerability affects AMD processors with affected SMU firmware versions; patches are available via AMD security bulletin AMD-SB-6018.
Affected products
- AMD System Management Unit firmware
Timeline
- 2026-08-31: disclosed