Home

Description

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.

PUBLISHED Reserved 2023-04-27 | Published 2026-02-11 | Updated 2026-02-11 | Assigner AMD




HIGH: 7.1CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L

Problem types

CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

Product status

Default status
affected

AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10)
unaffected

Default status
affected

AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10)
unaffected

Default status
affected

ROCm 6.4
unaffected

Default status
affected

ROCm 6.4
unaffected

Default status
affected

ROCm 6.4
unaffected

Default status
affected

ROCm 6.4
unaffected

References

www.amd.com/...es/product-security/bulletin/AMD-SB-6024.html

cve.org (CVE-2023-31324)

nvd.nist.gov (CVE-2023-31324)

Download JSON