Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution.

Project Subscriptions

Vendors Products
Instinct Mi210 Subscribe
Instinct Mi250 Subscribe
Instinct Mi300a Subscribe
Instinct Mi300x Subscribe
Instinct Mi308x Subscribe
Instinct Mi325x Subscribe
Radeon Pro V620 Subscribe
Radeon Pro V710 Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 15 May 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd instinct Mi210
Amd instinct Mi250
Amd instinct Mi300a
Amd instinct Mi300x
Amd instinct Mi308x
Amd instinct Mi325x
Amd radeon Pro V620
Amd radeon Pro V710
Vendors & Products Amd
Amd instinct Mi210
Amd instinct Mi250
Amd instinct Mi300a
Amd instinct Mi300x
Amd instinct Mi308x
Amd instinct Mi325x
Amd radeon Pro V620
Amd radeon Pro V710

Fri, 15 May 2026 04:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in AMD GPU Diagnostic IOCTL Enables Local Privilege Escalation

Fri, 15 May 2026 03:00:00 +0000

Type Values Removed Values Added
Description Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution.
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-05-15T02:44:54.735Z

Reserved: 2025-07-23T15:01:52.882Z

Link: CVE-2025-54517

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-15T03:16:22.493

Modified: 2026-05-15T03:16:22.493

Link: CVE-2025-54517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-15T11:15:25Z

Weaknesses