CVE-2026-0482
Received Received - Intake

AMD Versal SoC USB Boot Buffer Overflow

Vulnerability report for CVE-2026-0482, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Advanced Micro Devices Inc.

Description

In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled through board modifications—could allow crafted images to trigger a buffer overflow and overwrite an active function pointer, which may result in arbitrary code execution during boot process. This condition could lead to potential impacts on confidentiality, integrity, and availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amd versal_adaptive_soc *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects AMD Versal Adaptive SoC devices when USB boot mode is enabled through board modifications. Crafted images could trigger a buffer overflow, overwriting a function pointer and potentially allowing arbitrary code execution during the boot process.

Detection Guidance

Detection requires checking for unauthorized modifications enabling USB boot mode and analyzing boot images for crafted content. No specific commands are provided in the context.

Impact Analysis

The vulnerability may lead to arbitrary code execution during boot, potentially compromising confidentiality, integrity, and availability of the system. Attackers could exploit this to gain control over the device.

Compliance Impact

The vulnerability could lead to arbitrary code execution during boot, potentially compromising confidentiality, integrity, and availability of data. This may impact compliance with GDPR (data protection) and HIPAA (health data security) by increasing risks of unauthorized access or data breaches.

Mitigation Strategies

Disable USB boot mode if enabled through board modifications. Ensure only signed and verified boot images are used. Monitor for unexpected behavior during system boot.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0482. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart