Executive brief
A security vulnerability exists in the firmware responsible for managing power on certain AMD hardware. A local user with low-level access could exploit this flaw to cause a partial system crash or access restricted information. This could impact the stability of the device and the confidentiality of some internal data.
Technical details
An out-of-bounds read (CWE-125) exists within the AMD power management firmware. The vulnerability is triggered when the firmware reads data past the end of the intended buffer. A local attacker with low privileges can exploit this to access sensitive information or cause a partial denial-of-service (availability loss). The attack requires local access to the system but does not require high privileges or user interaction. AMD has addressed this in security bulletin AMD-SB-6027.
Affected products
- AMD Power Management Firmware
Timeline
- 2026-05-15: disclosed: Initial NVD publication date