Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.
Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.
| Vendor | Product | Versions |
|---|---|---|
| — | AMD / AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics; | — |
| — | AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics — AMD Software: Adrenalin Edition 25.5.1, AMD Software: PRO Edition 25.Q2 | — |
| AMD | AMD Ryzen™ AI MAX Series Processors | AMD Software: Adrenalin Edition 25.5.1, AMD Software: PRO Edition 25.Q2 |
| AMD | AMD Ryzen™ AI 300 Series Processors | AMD Software: Adrenalin Edition 25.5.1, AMD Software: PRO Edition 25.Q2 |
| AMD | AMD Ryzen™ 8000 Series Desktop Processors | AMD Software: Adrenalin Edition 25.5.1, AMD Software: PRO Edition 25.Q2 |
| AMD | AMD Ryzen™ Embedded 8000 Series Processors | Q2 - 2025 AMD Embedded Ryzen[7000 8000 9000] Windows® Catalyst™ driver [25.6.1] (68926) |
| AMD | AMD Ryzen™ Embedded 7000 Series Processors | Q2 - 2025 AMD Embedded Ryzen[7000 8000 9000] Windows® Catalyst™ driver [25.6.1] (68926) |
| AMD | AMD Ryzen™ Embedded 9000 Series Processors | Q2 - 2025 AMD Embedded Ryzen[7000 8000 9000] Windows® Catalyst™ driver [25.6.1] (68926) |
| AMD | AMD Radeon™ RX 7000 Series Graphics Products | 25.5.1 (25.10.01.09), AMD Software: PRO Edition 25.Q2(25.10.10), Radeon Software For Linux 25.10.1 |
| AMD | AMD Radeon™ PRO W7000 Series Graphics Products | 25.5.1 (25.10.01.09), AMD Software: PRO Edition 25.Q2(25.10.10), Radeon Software For Linux 25.10.1 |
| AMD | AMD Instinct™ MI300X | ROCm 6.2.4 |
| AMD | AMD Instinct™ MI300A | ROCm 6.2.4 |
| AMD | AMD Instinct™ MI308X | ROCm 6.2.4 |
| AMD | AMD Instinct™ MI325X | ROCm 6.2.4 |
| AMD | AMD Radeon™ PRO V710 | Contact your AMD Customer Engineering representative |
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.