CVE-2025-0003

7.3

AMD · Xilinx Run Time (XRT)

A use-after-free vulnerability in AMD Xilinx Run Time caused by improper resource locking allows local attackers to compromise system confidentiality or availability.

Executive summary

A local use-after-free vulnerability in AMD Xilinx Run Time (XRT) poses a high risk to system confidentiality and availability.

Vulnerability

The vulnerability stems from improper resource locking (CWE-413) within the Xilinx Run Time environment. A local attacker with low privileges can trigger a use-after-free condition to influence system memory, potentially leading to unauthorized data access or service disruption.

Business impact

Successful exploitation allows a local user to impact the stability and security of systems utilizing Xilinx acceleration hardware. Given the CVSS score of 7.3, this flaw presents a high risk to organizations where local access is provided to untrusted users or where multi-tenant environments share hardware resources. Unauthorized access to sensitive data processed by the runtime or unexpected system reboots could result in significant operational downtime.

Remediation

Immediate Action: Update the AMD Xilinx Run Time (XRT) environment to version 2025.1 or later as specified in the official AMD security bulletin.

Proactive Monitoring: Monitor system logs for unexpected process crashes or segmentation faults within the XRT stack that may indicate exploitation attempts.

Compensating Controls: Restrict local system access to authorized personnel only to prevent malicious actors from reaching the vulnerable XRT interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

While the vulnerability requires local access, the nature of use-after-free flaws can often lead to more severe outcomes than simple denial of service. Organizations should prioritize patching XRT installations to version 2025.1 to ensure the underlying locking mechanisms are correctly implemented, thereby neutralizing the risk of memory corruption.

More AMD CVEs

Sources

Originally found and disclosed by Reported through AMD Bug Bounty Program, per the CVE Program record.