CVE-2025-66664: AMD Instinct MI210
Medium severity, CVSS 4.6. EPSS: 0.1% chance of exploitation in the next 30 days.
Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory contents exposure or an exception
Affected products
- AMD AMD Instinct MI210
- AMD AMD Instinct MI250
- AMD AMD Instinct MI300A
- AMD AMD Instinct MI300X
- AMD AMD Instinct MI308X
- AMD AMD Instinct MI325X
- AMD AMD Radeon Pro v520
- AMD AMD Radeon Pro v620
- AMD AMD Radeon Pro v710
- AMD AMD Radeon Pro w6000 Series Graphics Products
- AMD AMD Radeon Pro w7000 Series Graphics Products
- AMD AMD Radeon Rx 6000 Series Graphics Products
- AMD AMD Radeon Rx 7000 Series Graphics Products
Published 2026-05-15. Last modified 2026-06-17.