Junglewise Threat Intelligence

CVE-2026-28237: AMD uProf unrestricted resource allocation

CVE-2026-28237 · Severity: info · CVSS 6.8 · Published 2026-06-09

Vendors: Amd.

Executive brief

AMD uProf, a performance analysis tool used by developers to optimize software on AMD processors, contains a vulnerability that allows for unrestricted resource allocation. A local user could exploit this flaw to consume excessive system resources, such as memory or CPU. This can lead to a system slowdown or a complete crash, resulting in a loss of availability for other users and services on the machine.

Technical details

A vulnerability classified as CWE-770 (Allocation of Resources Without Limits or Throttling) exists in AMD uProf. The flaw allows a local attacker with low privileges to trigger unrestricted resource allocation within the application. By exhausting system resources such as memory or processing power, the attacker can cause a denial-of-service (DoS) condition on the host system. The attack vector is local, meaning the attacker must already have access to the system to execute the exploit. AMD has released a security bulletin (AMD-SB-9025) regarding this issue.

Affected products

  • AMD uProf

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats