CVE-2026-0461 PUBLISHED

Assigner: AMD
Reserved: 06.12.2025 Published: 05.10.2026 Updated: 06.10.2026

Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process. This issue could impact the confidentiality, integrity, or availability of affected system.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.5

Product Status

Vendor AMD
Product Zynq™ UltraScale+ MPSoCs
Versions Default: affected
  • Version 2026.1 is unaffected
Vendor AMD
Product Zynq™ UltraScale+ RFSoCs
Versions Default: affected
  • Version 2026.1 is unaffected
Vendor AMD
Product Kria SOMs
Versions Default: affected
  • Version 2026.1 is unaffected

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE