Executive brief
A security vulnerability exists in the driver for the AMD Secure Processor, a dedicated security chip found in many AMD-based computers. An attacker with high-level administrative access could exploit this flaw to read sensitive information from the processor's memory or cause a system crash. This could lead to the exposure of internal system data or a disruption of operations.
Technical details
An out-of-bounds read vulnerability exists in the AMD Secure Processor (ASP) TEE SOC Driver due to insufficient parameter sanitization. A local attacker with high privileges (PR:H) can issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to the driver. Successful exploitation can lead to the exposure of SOC Driver memory contents or trigger a system exception (denial of service). The vulnerability is tracked as CWE-125 and affects the TEE SOC Driver component.
Affected products
- AMD Secure Processor (ASP) TEE SOC Driver
Timeline
- 2026-05-15: advisory: Initial disclosure by AMD and NVD publication.