By vendor

Amd vulnerabilities

Known CVEs affecting Amd products, prioritized by severity, with SEC.co remediation and detection guidance.

3 published vulnerabilities

  • CVE-2026-49121HIGH 8.1

    AI Tensor Engine for ROCm (AITER) versions up to 0.1.14 contain a critical flaw that allows attackers to run arbitrary code on inference worker machines without authentication. An attacker who can reach certain network endpoints or forge specific credentials can send a specially crafted message that executes code with the privileges of the inference worker process across multiple nodes simultaneously. This vulnerability requires network access to specific cluster communication channels but bypasses all authentication and validation mechanisms.

  • CVE-2026-0466MEDIUM 5.5

    AMD uProf, a performance profiling tool, contains an access control vulnerability that allows a user with local system access to write data into memory regions normally reserved for the kernel. This weakness could crash the system or render it temporarily unavailable. The vulnerability requires an attacker to already have an account on the target system—it cannot be exploited remotely.

  • CVE-2026-28237MEDIUM 5.5

    AMD uProf, a performance profiling tool used by developers and system administrators, contains a flaw in how it allocates system resources. An authenticated local user can trigger excessive resource consumption—such as memory or CPU—causing the application or system to become unresponsive or crash. This is a localized availability issue that does not expose data or allow privilege escalation, but it can disrupt legitimate work on affected machines.