Executive brief
The AMD Device Metrics Exporter, a tool used to monitor GPU performance in the ROCm ecosystem, contains a vulnerability that allows it to listen for connections on all available network interfaces. This could allow a remote attacker to gain unauthorized access to GPU management functions. An exploit could lead to unauthorized changes in GPU configuration, potentially causing system instability or a complete loss of service availability.
Technical details
The AMD Device Metrics Exporter is vulnerable to CWE-1327 (Binding to an Unrestricted IP Address). By default, the service binds to all available network interfaces (0.0.0.0) rather than a specific local or restricted address. A remote, unauthenticated attacker with network access to the exporter's port can interact with the service to modify GPU configurations. This can lead to a denial-of-service (DoS) condition by disrupting GPU operations. Users are advised to consult AMD security bulletin AMD-SB-6031 for mitigation or patching information.
Affected products
- AMD Device Metrics Exporter (ROCm ecosystem)
Timeline
- 2026-05-15: disclosed
- 2026-05-15: advisory: AMD-SB-6031 published