CVE-2023-20548 PUBLISHED

Assigner: AMD
Reserved: 27.10.2022 Published: 11.02.2026 Updated: 11.02.2026

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L
CVSS Score: 7.1

Product Status

Vendor AMD
Product AMD Radeon™ RX 5000 Series Graphics Products
Versions Default: affected
  • Version AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10) is unaffected
Vendor AMD
Product AMD Radeon™ PRO W5000 Series Graphics Products
Versions Default: affected
  • Version AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10) is unaffected
Vendor AMD
Product AMD Radeon™ VII
Versions Default: affected
  • Version No fix planned is unaffected
Vendor AMD
Product AMD Radeon™ PRO VII
Versions Default: affected
  • Version No fix planned is unaffected
Vendor AMD
Product AMD Instinct™ MI210
Versions Default: affected
  • Version ROCm 6.2 is unaffected
Vendor AMD
Product AMD Instinct™ MI250
Versions Default: affected
  • Version ROCm 6.2 is unaffected
Vendor AMD
Product AMD Instinct™ MI300X
Versions Default: affected
  • Version ROCm 6.2 is unaffected
Vendor AMD
Product AMD Instinct™ MI300A
Versions Default: affected
  • Version ROCm 6.2 is unaffected

References

Problem Types

  • CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition CWE