CVE-2025-48507: AMD Kria Som

High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.

The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.

Affected products

  • AMD Kria Som
  • AMD Zynq Ultrascale+ Mpsocs
  • AMD Zynq Ultrascale+ Rfsocs

Published 2025-11-23. Last modified 2026-06-17.