CVE-2023-31324: AMD Radeon Pro Vii Firmware

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.

Affected products

  • AMD Radeon Pro Vii Firmware: affected versions not specified
  • AMD Radeon Software: before 25.q2 (fixed in 25.q2); before 24.6.1 (fixed in 24.6.1)
  • AMD Radeon Vii Firmware: affected versions not specified
  • AMD Rocm: before 6.2.0 (fixed in 6.2.0)

Published 2026-02-11. Last modified 2026-06-17.