CVE-2025-0005

7.3

AMD · Xilinx Run Time (XRT)

An integer overflow vulnerability in the XOCL driver of AMD Xilinx Run Time (XRT) may allow a local attacker to cause a system crash or denial of service.

Executive summary

A local integer overflow vulnerability in the AMD Xilinx Run Time (XRT) driver poses a risk of system instability and denial of service.

Vulnerability

The vulnerability is an integer overflow (CWE-190) occurring due to improper input validation within the XOCL driver. The CVSS vector (AV:L/AC:L/PR:N/UI:N) indicates that this flaw can be triggered by a local attacker without requiring specific user interaction or elevated privileges.

Business impact

The primary impact of this vulnerability is a denial of service, which can lead to unplanned system downtime and loss of service availability. With a CVSS score of 7.3, this is categorized as a High severity issue, as it permits local users to disrupt critical compute operations managed by the XRT framework.

Remediation

Immediate Action: Update the AMD Xilinx Run Time (XRT) software to version 2025.1 or later to implement the necessary input validation fixes.

Proactive Monitoring: Monitor system logs for unexpected driver crashes or kernel-level errors that may indicate an attempt to trigger the overflow condition.

Compensating Controls: Restrict local system access to authorized personnel only, as the vulnerability requires local execution to trigger the overflow.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the High severity of this integer overflow vulnerability, organizations should prioritize updating the Xilinx Run Time (XRT) driver across all affected infrastructure. Timely patching is the most effective method to prevent potential denial of service attacks that could impact compute-intensive environments.

More AMD CVEs

Sources

Originally found and disclosed by Reported through AMD Bug Bounty Program, per the CVE Program record.