Executive brief
A security vulnerability exists in the AMD TEE SOC Driver, which manages secure communication between the main processor and the security subsystem. An attacker with high-level administrative access could exploit this flaw to cause memory mapping errors, potentially leading to system instability or unexpected behavior. This issue primarily impacts the reliability and integrity of secure operations within the hardware environment.
Technical details
A vulnerability classified as Improper Validation of Specified Quantity in Input (CWE-1284) exists in the AMD TEE SOC Driver. The flaw is located in the handling of the DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT command, where insufficient parameter sanitization allows for malformed inputs. An attacker with local access and high privileges (PR:H) can exploit this to trigger incorrect shared memory mapping. While the CVSS score is low (1.8), the primary impact is on availability (VA:L), potentially leading to unexpected system behavior or crashes in the Trusted Execution Environment (TEE) context.
Affected products
- AMD TEE SOC Driver
Timeline
- 2026-05-15: advisory: AMD published security bulletin AMD-SB-6027
- 2026-05-15: disclosed: CVE-2025-66660 published to NVD dataset