CVE-2023-31324

EUVD-2023-35635
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.
TOCTOU
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
amdrocm
𝑥
< 6.2.0
amdradeon_software
𝑥
< 25.q2
amdradeon_pro_vii_firmware
-
amdradeon_software
𝑥
< 24.6.1
amdradeon_vii_firmware
-
𝑥
= Vulnerable software versions