Description
A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash
Published: 2026-05-15
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow exists in the AMD Sensor Fusion Hub Driver, allowing a local attacker to write beyond the bounds of an internal buffer by triggering a memory write operation. The flaw is classified as CWE-120, and its exploitation can cause the driver—and potentially the system—to crash or become unstable, resulting in a denial of service. No unauthorized code execution or data disclosure is described, so the primary impact is availability disruption rather than confidentiality or integrity compromise.

Affected Systems

The vulnerability affects a broad range of AMD mobile processors and embedded platforms, including the Athlon 3000 Series, RYZEN 7000 is embedded, Ryzen 3000–8000 mobile series, and the Ryzen AI and Embedded 8000 series. The vendor notes that the issue manifests in any device that utilizes the Sensor Fusion Hub Driver, but specific firmware or BIOS levels are not enumerated, so any system running the driver should be assumed potentially impacted.

Risk and Exploitability

The CVSS score of 6.8 reflects a moderate severity that requires local privileges or physical access to leverage the exploit. EPSS data are not available, suggesting no widespread exploitation reports yet, and the vulnerability is not listed in CISA’s KEV catalog. Because the attack vector is local, the risk to remote users is minimized, but users who have administrative or privileged access to the affected device should consider the possibility of a service outage if the driver crashes during operation.

Generated by OpenCVE AI on May 15, 2026 at 05:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the AMD SB-4015 security bulletin patch to update the Sensor Fusion Hub Driver firmware. This is the definitive fix provided by AMD and should be deployed on all affected machines.
  • If the driver’s functionality is not essential to your use case, temporarily disable or uninstall the Sensor Fusion Hub Driver to prevent crashes until the patch is applied.
  • Configure the device’s BIOS/UEFI settings to disable the Sensor Fusion Hub hardware function until the firmware update is available to reduce the attack surface.

Generated by OpenCVE AI on May 15, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 15 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 May 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Buffer Overflow in AMD Sensor Fusion Hub Driver May Cause Denial of Service

Fri, 15 May 2026 03:00:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-05-15T13:28:56.693Z

Reserved: 2025-03-12T15:15:04.910Z

Link: CVE-2025-29944

cve-icon Vulnrichment

Updated: 2026-05-15T13:28:52.133Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-15T03:16:21.937

Modified: 2026-05-15T14:10:17.083

Link: CVE-2025-29944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-15T05:30:36Z

Weaknesses