🔐 CVE Alert

CVE-2026-0461

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process. This issue could impact the confidentiality, integrity, or availability of affected system.

CWE CWE-787
Vendor amd
Product zynq™ ultrascale+ mpsocs
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for amd zynq™ ultrascale+ mpsocs

Be the first to know when new unknown vulnerabilities affecting amd zynq™ ultrascale+ mpsocs are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

AMD / Zynq™ UltraScale+ MPSoCs
All versions affected
AMD / Zynq™ UltraScale+ RFSoCs
All versions affected
AMD / Kria SOMs
All versions affected

References

NVD ↗ CVE.org ↗ EPSS Data ↗
amd.com: https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-8029.html