Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | USB Boot Mode Buffer Overflow in AMD Zynq UltraScale+ MPSoCs and RFSoCs |
Mon, 05 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process. This issue could impact the confidentiality, integrity, or availability of affected system. | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: AMD
Published:
Updated: 2026-10-05T21:38:01.104Z
Reserved: 2025-12-06T15:11:19.042Z
Link: CVE-2026-0461
No data.
Status : Received
Published: 2026-10-05T22:16:55.280
Modified: 2026-10-05T22:16:55.280
Link: CVE-2026-0461
No data.
OpenCVE Enrichment
Updated: 2026-10-05T22:30:19Z
-
CWE-787
Out-of-bounds Write