CVE-2025-0005
7.3AMD · Xilinx Run Time (XRT)
An integer overflow vulnerability in the XOCL driver of AMD Xilinx Run Time (XRT) may allow a local attacker to cause a system crash or denial of service.
Executive summary
A local integer overflow vulnerability in the AMD Xilinx Run Time (XRT) driver poses a risk of system instability and denial of service.
Vulnerability
The vulnerability is an integer overflow (CWE-190) occurring due to improper input validation within the XOCL driver. The CVSS vector (AV:L/AC:L/PR:N/UI:N) indicates that this flaw can be triggered by a local attacker without requiring specific user interaction or elevated privileges.
Business impact
The primary impact of this vulnerability is a denial of service, which can lead to unplanned system downtime and loss of service availability. With a CVSS score of 7.3, this is categorized as a High severity issue, as it permits local users to disrupt critical compute operations managed by the XRT framework.
Remediation
Immediate Action: Update the AMD Xilinx Run Time (XRT) software to version 2025.1 or later to implement the necessary input validation fixes.
Proactive Monitoring: Monitor system logs for unexpected driver crashes or kernel-level errors that may indicate an attempt to trigger the overflow condition.
Compensating Controls: Restrict local system access to authorized personnel only, as the vulnerability requires local execution to trigger the overflow.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity of this integer overflow vulnerability, organizations should prioritize updating the Xilinx Run Time (XRT) driver across all affected infrastructure. Timely patching is the most effective method to prevent potential denial of service attacks that could impact compute-intensive environments.
More AMD CVEs
Sources
Originally found and disclosed by Reported through AMD Bug Bounty Program, per the CVE Program record.