CVE-2023-31339: AMD Trusted Firmware-A

Medium severity, CVSS 5.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.

Affected products

  • AMD Trusted Firmware-A: before 2023.2 (fixed in 2023.2)
  • Trustedfirmware Trusted Firmware-A: before 2.10.1 (fixed in 2.10.1)

Published 2024-08-13. Last modified 2026-06-17.