CVE-2025-52539
7.3AMD · Xilinx Run Time (XRT)
A stack-based buffer overflow in the AMD Xilinx Run Time Environment may allow a local attacker to read or corrupt AXI data, impacting system confidentiality, integrity, and availability.
Executive summary
A stack-based buffer overflow vulnerability in AMD Xilinx Run Time (XRT) creates a significant risk of local data corruption and system compromise.
Vulnerability
This vulnerability is a stack-based buffer overflow (CWE-121) within the Xilinx Run Time Environment. The flaw allows a local attacker, leveraging the lack of authentication required by the vector, to interact with the advanced extensible interface to read or corrupt sensitive data.
Business impact
The potential for unauthorized data access and system instability poses a notable risk to operational integrity. Given the CVSS score of 7.3, this high-severity flaw could allow an attacker with local access to disrupt critical processes or exfiltrate data, which may lead to significant operational downtime or the compromise of proprietary information processed via the AXI interface.
Remediation
Immediate Action: Update the AMD Xilinx Run Time (XRT) environment to version 2025.1 or later to apply the necessary security fixes provided by the vendor.
Proactive Monitoring: Monitor system logs for unauthorized attempts to access or manipulate the XRT interfaces and watch for unexpected process crashes that may indicate exploitation attempts.
Compensating Controls: Restrict local system access to authorized personnel only and implement strict host-based access controls to limit the ability of unauthorized users to interact with the XRT software.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing AMD Xilinx Run Time (XRT) must prioritize the transition to version 2025.1 to mitigate this buffer overflow vulnerability. Because the flaw permits local data corruption and potential system-wide impacts, applying the vendor-supplied update is the only effective method for ensuring long-term security and system reliability.
More AMD CVEs
Sources
Originally found and disclosed by Reported through AMD Bug Bounty Program, per the CVE Program record.