Executive brief
A security flaw in the AMD TEE SOC Driver could allow a highly privileged local user to send malformed commands to the system's hardware components. This could result in invalid data being written to internal processor components, potentially causing system instability or unexpected behavior. Because the attack requires administrative access and specific hardware conditions, the overall risk to most operations is considered low.
Technical details
A vulnerability classified as Improper Validation of Specified Quantity in Input (CWE-1284) exists in the AMD TEE SOC Driver. The flaw stems from insufficient sanitization of parameters within the DRV_SOC_CMD_ID_SRIOV_COPY_VF_CHIPLET_REGS command. A local attacker with high privileges (PR:H) can exploit this to write invalid data to a remote Die (chiplet). While the attack complexity is high (AC:H), successful exploitation could result in a loss of availability or unexpected hardware state. The vulnerability was disclosed by AMD in advisory AMD-SB-6027.
Affected products
- AMD TEE SOC Driver
Timeline
- 2026-05-15: disclosed: Initial publication of CVE-2026-0428
- 2026-05-15: advisory: AMD security bulletin AMD-SB-6027 released