Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-01988

Опубликовано: 10 фев. 2026
Источник: fstec
CVSS3: 6.3
CVSS2: 4.9
EPSS Низкий

Описание

Уязвимость интерфейса PCIe микропрограммного обеспечения графических процессоров AMD связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Advanced Micro Devices Inc.

Наименование ПО

AMD Ryzen 3000 Series Desktop
AMD Ryzen 4000 Series Desktop processors with Radeon graphics
AMD Ryzen 5000 Series Desktop processor with Radeon graphics
AMD Ryzen 5000 Series Mobile processor with Radeon graphics
AMD Ryzen 5000 Series Desktop Processors
AMD Ryzen 7020 Series Processors with Radeon Graphics
AMD EPYC Embedded 7002
AMD Ryzen Embedded 5000
AMD Ryzen Embedded V2000
AMD Ryzen Embedded V3000
AMD EPYC 7002 Series
AMD Ryzen Threadripper PRO 3000 WX-Series
AMD Ryzen Embedded 7000
AMD Ryzen 8000 Series Processor with Radeon Graphics Phoenix
AMD Ryzen Threadripper PRO 9000 WX-Series Processors
AMD Ryzen Z1 Series Processors
AMD Ryzen 4000 Series Desktop Processors
AMD Ryzen 7000 Series Desktop Processors with Radeon Graphics
AMD Ryzen 7045 Series Processors with Radeon Graphics
AMD Ryzen Embedded 8000

Версия ПО

- (AMD Ryzen 3000 Series Desktop)
- (AMD Ryzen 4000 Series Desktop processors with Radeon graphics)
- (AMD Ryzen 5000 Series Desktop processor with Radeon graphics)
- (AMD Ryzen 5000 Series Mobile processor with Radeon graphics)
- (AMD Ryzen 5000 Series Desktop Processors)
- (AMD Ryzen 7020 Series Processors with Radeon Graphics)
- (AMD EPYC Embedded 7002)
- (AMD Ryzen Embedded 5000)
- (AMD Ryzen Embedded V2000)
- (AMD Ryzen Embedded V3000)
- (AMD EPYC 7002 Series)
- (AMD Ryzen Threadripper PRO 3000 WX-Series)
- (AMD Ryzen Embedded 7000)
- (AMD Ryzen 8000 Series Processor with Radeon Graphics Phoenix)
- (AMD Ryzen Threadripper PRO 9000 WX-Series Processors)
- (AMD Ryzen Z1 Series Processors)
- (AMD Ryzen 4000 Series Desktop Processors)
- (AMD Ryzen 7000 Series Desktop Processors with Radeon Graphics)
- (AMD Ryzen 7045 Series Processors with Radeon Graphics)
- (AMD Ryzen Embedded 8000)

Тип ПО

Микропрограммный код
Микропрограммный код аппаратных компонентов компьютера
ПО программно-аппаратного средства

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,9)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 6,3)
Средний уровень опасности (оценка CVSS 4.0 составляет 6)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4013.html

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 23%
0.00307
Низкий

6.3 Medium

CVSS3

4.9 Medium

CVSS2

Связанные уязвимости

nvd
6 месяцев назад

Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack against the host resulting in loss of availability.

github
6 месяцев назад

Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack against the host resulting in loss of availability.

EPSS

Процентиль: 23%
0.00307
Низкий

6.3 Medium

CVSS3

4.9 Medium

CVSS2