CVE-2023-31323 PUBLISHED

Assigner: AMD
Reserved: 27.04.2023 Published: 12.02.2026 Updated: 12.02.2026

Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of confidentiality, integrity, or availability.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L
CVSS Score: 8.4

Product Status

Vendor AMD
Product AMD Radeon™ RX 5000 Series Graphics Products
Versions Default: affected
  • Version AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10) is unaffected
Vendor AMD
Product AMD Radeon™ PRO W5000 Series Graphics Products
Versions Default: affected
  • Version AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10) is unaffected
Vendor AMD
Product AMD Radeon™ VII
Versions Default: affected
  • Version No fix planned is affected
Vendor AMD
Product AMD Radeon™ PRO VII
Versions Default: affected
  • Version No fix planned is affected
Vendor AMD
Product AMD Instinct™ MI250
Versions Default: affected
  • Version ROCm 6.2 is unaffected
Vendor AMD
Product AMD Instinct™ MI300A
Versions Default: affected
  • Version ROCm 6.2 is unaffected
Vendor AMD
Product AMD Instinct™ MI210
Versions Default: affected
  • Version ROCm 6.2 is unaffected
Vendor AMD
Product AMD Instinct™ MI300X
Versions Default: affected
  • Version ROCm 6.2 is unaffected

References

Problem Types

  • CWE-843 Access of Resource Using Incompatible Type (‘Type Confusion’) CWE