CVE-2026-0461
Received Received - Intake

Insufficient Boundary Validation in AMD Zynq UltraScale+ MPSoC RFSoC USB Boot Mode

Vulnerability report for CVE-2026-0461, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Advanced Micro Devices Inc.

Description

Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process. This issue could impact the confidentiality, integrity, or availability of affected system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
amd zynq_ultrascale_plus_mpsoc *
amd rfsoc *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves insufficient boundary validation in the USB boot mode of AMD Zynq UltraScale+ MPSoC and RFSoC devices. Unbounded DFU download requests can overflow the DDR receive buffer into FSBL memory, potentially allowing unauthorized code execution during the boot process.

Detection Guidance

This vulnerability involves insufficient boundary validation in USB boot mode of AMD Zynq UltraScale+ MPSoC and RFSoC devices. Detection requires checking for abnormal DFU download requests or buffer overflows during boot. No specific commands are provided in the context to detect this issue.

Impact Analysis

This vulnerability could allow attackers to execute unauthorized code during system boot, potentially compromising confidentiality, integrity, or availability of the affected system. It may lead to data breaches, system crashes, or unauthorized access if exploited.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially violating data protection requirements under GDPR or HIPAA. Non-compliance may result from compromised data confidentiality or integrity during system boot.

Mitigation Strategies

Apply AMD's official firmware update for Zynq UltraScale+ MPSoC and RFSoC devices to correct the boundary validation issue in USB boot mode. Disable USB boot mode if not required and restrict physical access to affected systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0461. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart