VYPR
High severity7.8NVD Advisory· Published Feb 11, 2026· Updated Jun 17, 2026

CVE-2023-20548

CVE-2023-20548

Description

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.

Affected products

14
  • cpe:2.3:a:amd:radeon_software:*:*:*:*:adrenalin:*:*:*+ 1 more
    • cpe:2.3:a:amd:radeon_software:*:*:*:*:adrenalin:*:*:*range: <24.6.1
    • cpe:2.3:a:amd:radeon_software:*:*:*:*:pro:*:*:*range: <25.q2
  • cpe:2.3:a:amd:rocm:*:*:*:*:*:*:*:*
    Range: <6.2.0
  • cpe:2.3:o:amd:radeon_pro_vii_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:amd:radeon_vii_firmware:-:*:*:*:*:*:*:*
  • AMD/AMD Instinct™ MI210v5
    Range: ROCm 6.2
  • AMD/AMD Instinct™ MI250v5
    Range: ROCm 6.2
  • Range: ROCm 6.2
  • Range: ROCm 6.2
  • AMD/AMD Radeon™ PRO VIIv5
    Range: No fix planned
  • AMD/AMD Radeon™ PRO W5000 Series Graphics Productsv5
    Range: AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10)
  • AMD/AMD Radeon™ RX 5000 Series Graphics Productsv5
    Range: AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10)
  • AMD/AMD Radeon™ VIIv5
    Range: No fix planned

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.