CVE-2025-52538

8.0

AMD · Xilinx Run Time (XRT)

An integer overflow vulnerability in the XOCL driver of AMD Xilinx Run Time (XRT) allows a local attacker to compromise system confidentiality or availability.

Executive summary

A local integer overflow vulnerability in the AMD Xilinx Run Time (XRT) driver, identified as CVE-2025-52538, presents a significant risk of unauthorized data access or system disruption.

Vulnerability

This vulnerability is caused by improper input validation within the XOCL driver, which facilitates an integer overflow condition when triggered by a local attacker. The vulnerability requires local access but does not necessitate specific user privileges (PR:N).

Business impact

Successful exploitation of this integer overflow can lead to a loss of system confidentiality or availability, potentially enabling an attacker to read sensitive data or crash the affected system. Given the CVSS score of 8.0, this is categorized as a high-severity flaw, necessitating prompt remediation to prevent local privilege escalation or denial-of-service scenarios.

Remediation

Immediate Action: Update the AMD Xilinx Run Time (XRT) to version 2025.1 or later to address the vulnerable XOCL driver.

Proactive Monitoring: Monitor system logs for unusual driver activity or unexpected process crashes that may indicate an attempt to trigger the integer overflow.

Compensating Controls: Restrict local access to the affected system to authorized users only, as the vulnerability requires local interaction to exploit.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

The high CVSS score reflects the serious potential for system-level impact should an attacker successfully trigger the integer overflow. IT administrators should prioritize upgrading to the 2025.1 release of the Xilinx Run Time environment across all affected deployments to effectively eliminate this vulnerability.

More AMD CVEs

Sources

Originally found and disclosed by Reported through AMD Bug Bounty Program, per the CVE Program record.