Impact
A malicious virtual function can invoke specific command handlers in the SMU, leading to an out‑of‑bounds memory read that causes a denial of service. The weakness is an Integer Overflow or Wraparound, as identified by CWE‑129. The impact is limited to availability; an attacker could force the GPU or associated firmware to crash, potentially disrupting graphics rendering on the affected system.
Affected Systems
The vulnerability affects AMD Radeon Pro V620 graphics products. No specific firmware or driver versions are listed as affected in the advisory, so any device using current or legacy firmware may be vulnerable.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity. EPSS data is not available, and it is not listed in the CISA KEV catalog, suggesting that exploitation is not currently observed. The likely attack vector is via a malicious driver or firmware that can trigger the vulnerable virtual function, implying local or privileged access is required to execute the exploit.
OpenCVE Enrichment