CVE-2026-43606: AMD Vitis Libraries - Security Module
High severity, CVSS 8.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.
Affected products
- AMD Vitis Libraries - Security Module
- AMD Vitis Unified Installer For Fpgas & Adaptive Socs In Windows
Published 2026-08-11. Last modified 2026-08-12.