Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process. This issue could impact the confidentiality, integrity, or availability of affected system.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | USB Boot Mode Buffer Overflow in AMD Zynq UltraScale+ MPSoCs and RFSoCs |
Mon, 05 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process. This issue could impact the confidentiality, integrity, or availability of affected system. | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMD
Published:
Updated: 2026-10-05T21:38:01.104Z
Reserved: 2025-12-06T15:11:19.042Z
Link: CVE-2026-0461
No data.
Status : Received
Published: 2026-10-05T22:16:55.280
Modified: 2026-10-05T22:16:55.280
Link: CVE-2026-0461
No data.
OpenCVE Enrichment
Updated: 2026-10-05T22:30:19Z
Weaknesses