HIGH · 7.8

CVE-2023-31324

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are...

Vulnerability Description

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AmdRocm< 6.2.0
AmdInstinct Mi210-
AmdInstinct Mi250-
AmdInstinct Mi300A-
AmdInstinct Mi300X-
AmdRadeon Software< 25.q2
AmdRadeon Pro W5500-
AmdRadeon Pro W5500X-
AmdRadeon Pro W5700-
AmdRadeon Pro W5700X-
AmdRadeon Pro Vii Firmware-
AmdRadeon Pro Vii-
AmdRadeon Rx 5300-
AmdRadeon Rx 5300 Xt-
AmdRadeon Rx 5300M-
AmdRadeon Rx 5500-
AmdRadeon Rx 5500 Xt-
AmdRadeon Rx 5500M-
AmdRadeon Rx 5600-
AmdRadeon Rx 5600 Xt-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-31324?

CVE-2023-31324 is a vulnerability with a CVSS score of 7.8 (HIGH). A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are...

How severe is CVE-2023-31324?

CVE-2023-31324 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-31324?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Rocm, Amd Instinct Mi210, Amd Instinct Mi250, Amd Instinct Mi300A, Amd Instinct Mi300X.