CVE-2025-66664: AMD Instinct MI210

Medium severity, CVSS 4.6. EPSS: 0.1% chance of exploitation in the next 30 days.

Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory contents exposure or an exception

Affected products

  • AMD AMD Instinct MI210
  • AMD AMD Instinct MI250
  • AMD AMD Instinct MI300A
  • AMD AMD Instinct MI300X
  • AMD AMD Instinct MI308X
  • AMD AMD Instinct MI325X
  • AMD AMD Radeon Pro v520
  • AMD AMD Radeon Pro v620
  • AMD AMD Radeon Pro v710
  • AMD AMD Radeon Pro w6000 Series Graphics Products
  • AMD AMD Radeon Pro w7000 Series Graphics Products
  • AMD AMD Radeon Rx 6000 Series Graphics Products
  • AMD AMD Radeon Rx 7000 Series Graphics Products

Published 2026-05-15. Last modified 2026-06-17.