Input validation error in AMD products - CVE-2023-20509

 

Input validation error in AMD products - CVE-2023-20509

Published: August 30, 2024


Vulnerability identifier: #VU96631
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20509
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient validation of DRAM addresses in PMFW. A local user can perform a DMA read from an invalid DRAM address to SRAM and escalate privileges on the system.


Affected software

AMD Radeon PRO V520
AMD Radeon PRO V620
AMD Instinct MI200
Radeon RX 6000 Series
Radeon RX 7000 Series
Radeon PRO W6000 Series
Radeon PRO W7000 Series

How to mitigate CVE-2023-20509

Install updates from vendor's website.

Radeon RX 6000 Series - update to 23.12.1
Radeon RX 7000 Series - update to 23.12.1
Radeon PRO W6000 Series - update to 23.30.13.03
Radeon PRO W7000 Series - update to 23.30.13.03

External References