Allocation of Resources Without Limits or Throttling in AMD products - CVE-2026-28237
Published: June 22, 2026
Vulnerability identifier: #VU134998
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28237
CWE-ID: CWE-770
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to unrestricted resource allocation. A local user can bypass implemented security restrictions and perform a denial of service (DoS) attack.
Affected software
AMD uProf for Linux
AMD uProf for FreeBSD
AMD uProf for Windows
AMD uProf for FreeBSD
AMD uProf for Windows
How to mitigate CVE-2026-28237
Install updates from vendor's website.
AMD uProf for Linux - update to 5.3
AMD uProf for FreeBSD - update to 5.3
AMD uProf for Windows - update to 5.3
AMD uProf for FreeBSD - update to 5.3
AMD uProf for Windows - update to 5.3