Multiple researchers reported vulnerabilities within AMD Xilinx Run Time (XRT) drivers, particularly in user space XRT driver (XOCL). These drivers are delivered as part of the AMD XRT framework. Refer to the CVE Details section for further information on each of these vulnerabilities.
| CVE | CVE Description | CVSS Score |
|---|---|---|
| CVE-2025-52538 | Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in loss of confidentiality or availability. | 8.0 High CVSS3.1:/AV:L/AC:L/PR:N//UI:N/S:U/C:H/I:L/A:H 8.5 High CVSS4.0:/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CVE-2025-0003 | Inadequate lock protection with Xilinx Run Time may allow a local attacker to trigger a Use-After-Free condition, potentially resulting in loss of confidentiality or availability. | 7.3 High CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L 5.2 Medium CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N |
| CVE-2025-0005 | Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in a crash or denial of service. |
7.3 High |
| CVE-2025-52539 | A buffer overflow with the Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced extensible interface (AXI), potentially resulting in loss of confidentiality, integrity, and/or availability. |
7.3 (High)
|
| CVE-2025-0007 | Insufficient validation with the Xilinx Run Time framework could allow a local attacker to escalate privileges from the user space to the kernel space, potentially compromising confidentiality, integrity, and/or availability. |
5.7 Medium |