Junglewise Threat Intelligence

CVE-2026-0481: AMD Device Metrics Exporter unrestricted IP address binding

CVE-2026-0481 · Severity: info · CVSS 9.2 · Published 2026-05-15

Vendors: Amd.

Executive brief

The AMD Device Metrics Exporter, a tool used to monitor GPU performance in the ROCm ecosystem, contains a vulnerability that allows it to listen for connections on all available network interfaces. This could allow a remote attacker to gain unauthorized access to GPU management functions. An exploit could lead to unauthorized changes in GPU configuration, potentially causing system instability or a complete loss of service availability.

Technical details

The AMD Device Metrics Exporter is vulnerable to CWE-1327 (Binding to an Unrestricted IP Address). By default, the service binds to all available network interfaces (0.0.0.0) rather than a specific local or restricted address. A remote, unauthenticated attacker with network access to the exporter's port can interact with the service to modify GPU configurations. This can lead to a denial-of-service (DoS) condition by disrupting GPU operations. Users are advised to consult AMD security bulletin AMD-SB-6031 for mitigation or patching information.

Affected products

  • AMD Device Metrics Exporter (ROCm ecosystem)

Timeline

  • 2026-05-15: disclosed
  • 2026-05-15: advisory: AMD-SB-6031 published

References