Input validation error in AMD products - CVE-2026-43598

 

Input validation error in AMD products - CVE-2026-43598

Published: October 5, 2026


Vulnerability identifier: #VU153243
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43598
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to insufficient validation of user-supplied input in the AMD ROCm Communication Collectives Library (RCCL). A remote user can pass specially crafted input to the application and execute arbitrary code on the target system.


Affected software

AMD Instinct MI210
AMD Instinct MI250
AMD Instinct MI250X
AMD Instinct MI300A
AMD Instinct MI300X
AMD Instinct MI308X
AMD Instinct MI325X
AMD Instinct MI350X
AMD Instinct MI355X

How to mitigate CVE-2026-43598

Install updates from vendor's website.

AMD Instinct MI210 - update to 7.14
AMD Instinct MI250 - update to 7.14
AMD Instinct MI250X - update to 7.14
AMD Instinct MI300A - update to 7.14
AMD Instinct MI300X - update to 7.14
AMD Instinct MI308X - update to 7.14
AMD Instinct MI325X - update to 7.14
AMD Instinct MI350X - update to 7.14
AMD Instinct MI355X - update to 7.14

External References

Related Security Bulletins