CVE-2026-0461
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process. This issue could impact the confidentiality, integrity, or availability of affected system.
| CWE | CWE-787 |
| Vendor | amd |
| Product | zynq™ ultrascale+ mpsocs |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for amd zynq™ ultrascale+ mpsocs
Be the first to know when new unknown vulnerabilities affecting amd zynq™ ultrascale+ mpsocs are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
AMD / Zynq™ UltraScale+ MPSoCs
All versions affected AMD / Zynq™ UltraScale+ RFSoCs
All versions affected AMD / Kria SOMs
All versions affected