Junglewise Threat Intelligence

CVE-2025-54517: AMD Graphics Driver out-of-bounds write in AMDGV_CMD_GET_DIAG_DATA

CVE-2025-54517 · Severity: info · CVSS 8.5 · Published 2026-05-15

Vendors: Amd.

Executive brief

A security vulnerability exists in certain AMD graphics driver components used to manage hardware diagnostics. A local user with low privileges could exploit this flaw to gain full administrative control over the system. This could lead to unauthorized access to sensitive data, system instability, or the installation of persistent malware.

Technical details

An out-of-bounds (OOB) write vulnerability exists within the AMDGV_CMD_GET_DIAG_DATA ioctl handler of the AMD graphics driver. The flaw is categorized as CWE-787 and occurs when the handler fails to properly validate buffer boundaries during diagnostic data retrieval. A local attacker with low privileges can trigger this vulnerability by sending a specially crafted ioctl request. Successful exploitation allows the attacker to overwrite memory, potentially leading to local privilege escalation (LPE) or arbitrary code execution in the context of the kernel or a high-privileged service.

Affected products

  • AMD Graphics Driver

Timeline

  • 2026-05-15: disclosed: Initial public disclosure by AMD and NVD.

References