Executive brief
A vulnerability in the AMD Secure Processor PCI driver could allow a local user to cause a system crash or compromise the integrity of the platform. The affected component is responsible for managing secure operations within the hardware. An exploit could disrupt business operations through system instability or allow unauthorized changes to secure system states.
Technical details
A Use-After-Free (UAF) vulnerability exists in the AMD Secure Processor (ASP) PCI driver due to improper input validation. A local attacker with low privileges can exploit this flaw to trigger a memory corruption condition. Successful exploitation can lead to a denial-of-service (system crash) or a loss of platform integrity by manipulating memory that has already been freed. The vulnerability is tracked as CWE-416 and has been assigned a CVSS 4.0 base score of 6.9 by the vendor.
Affected products
- AMD Secure Processor (ASP) PCI driver
Timeline
- 2026-05-15: disclosed: Initial NVD publication date