Executive brief
AMD uProf, a performance analysis tool for AMD processors, contains a security flaw that could allow a local user to crash the system. By exploiting improper access controls, an attacker with standard user access can write data to protected memory areas shared with the operating system kernel. This can lead to a system-wide denial of service, disrupting operations and requiring a reboot.
Technical details
An improper access control vulnerability exists in AMD uProf (CWE-497). The flaw allows a local attacker with low-level user privileges to gain unauthorized write access to a kernel-shared memory section. This is achieved through local exploitation without requiring user interaction or complex attack timing. Successful exploitation can lead to memory corruption within the kernel space, resulting in a system crash or a persistent denial of service (DoS) condition. AMD has addressed this in security bulletin AMD-SB-9025.
Affected products
- AMD uProf
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory