Back to Database
Status published
High
CVE-2022-23817
Insufficient checking of memory buffer in AMD Secure Processor (ASP)...
Vulnerability Description
Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23817
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-5002.html
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4004.html
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-1029.html
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html
More from AMD
View All →CVE-2025-66664
Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC...
Medium
4.6
CVE-2025-66660
Insufficient parameter sanitization in TEE SOC Driver could allow an...
Low
1.8
CVE-2025-62628
Unsafe OpenSSL initialization within some AMD optional tools may allow...
High
7
CVE-2025-62627
An untrusted pointer dereference in the ionic cloud driver for...
High
7.2
CVE-2025-62626
Improper handling of insufficient entropy in the AMD CPUs could...
High
7.2
Affected Vendor
Affected Software
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ Threadripper™ PRO 3000 WX-Series Processors, AMD Ryzen™ 5000 Series Desktop Processors with Radeon™ Graphics, AMD Ryzen™ Threadripper™ PRO 5000 WX-Series Processors, AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 3000 Series Desktop Processors, AMD Ryzen™ 2000 Mobile Processors, AMD Ryzen™ 4000 Series Desktop Processors, AMD Ryzen™ 5000 Series Desktop Processors, AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics, AMD Ryzen™ Embedded R1000 Series Processors, AMD Ryzen™ Embedded R2000 Series Processors, AMD Ryzen™ Embedded 5000 Series Processors, AMD Ryzen™ Embedded V1000 Series Processors (formerly codenamed "Raven Ridge"), AMD Ryzen™ Embedded V1000 Series Processors (formerly codenamed "Picasso"), AMD Ryzen™ Embedded V2000 Series Processor, AMD Ryzen™ Embedded V3000 Series Processors, AMD Radeon™ RX 5000 Series Graphics Products, AMD Radeon™ PRO W5000 Series Graphics Products, AMD Radeon™ RX 6000 Series Graphics Products, AMD Radeon™ PRO W6000 Series Graphics Products, MI-25 / 50, MI-100, AMD Instinct™ MI250, AMD Instinct™ MI210
Vulnerable Versions:
PicassoPI-FP5 1.0.0.E, ChagallWSPI-sWRX8 1.0.0.5, CastlePeakWSPI-sWRX8 1.0.0.A, ComboAM4v2 PI 1.2.0.8, RenoirPI-FP6 1.0.0.A, CezannePI-FP6 1.0.0.C, ComboAM4V1 1.0.0.A, ComboAM4V2 1.2.0.9, ComboAM4PI 1.0.0.9, RembrandtPI-FP7_1.0.0.5, EmbeddedPI-FP5_1.2.0.A, EmbeddedR2KPI-FP5 1.0.0.2, EmbAM4PI 1.0.0.2, EmbeddedPI-FP6_1.0.0.8, EmbeddedPI-FP7r2_1002, AMD Software: Adrenalin Edition 22.5.2 (22.10.17.01), AMD Software: PRO Edition 22.Q2 (22.10.20), No fix planned, ROCm 6.4.2, ROCm 7.0
Timeline
Official Publish:
August 13th, 2024
Last Modified:
May 15th, 2026
Added to House:
July 21st, 2026