Executive brief
A security vulnerability exists in certain AMD graphics driver components used to manage hardware diagnostics. A local user with low privileges could exploit this flaw to gain full administrative control over the system. This could lead to unauthorized access to sensitive data, system instability, or the installation of persistent malware.
Technical details
An out-of-bounds (OOB) write vulnerability exists within the AMDGV_CMD_GET_DIAG_DATA ioctl handler of the AMD graphics driver. The flaw is categorized as CWE-787 and occurs when the handler fails to properly validate buffer boundaries during diagnostic data retrieval. A local attacker with low privileges can trigger this vulnerability by sending a specially crafted ioctl request. Successful exploitation allows the attacker to overwrite memory, potentially leading to local privilege escalation (LPE) or arbitrary code execution in the context of the kernel or a high-privileged service.
Affected products
- AMD Graphics Driver
Timeline
- 2026-05-15: disclosed: Initial public disclosure by AMD and NVD.