CVE-2025-66664 - CVE House
Back to Database
Status published Medium CVE-2025-66664

Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC...

Vulnerability Description

Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory contents exposure or an exception

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66664

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

AMD Radeon™ RX 6000 Series Graphics Products, AMD Radeon™ RX 7000 Series Graphics Products, AMD Radeon™ PRO W6000 Series Graphics Products, AMD Radeon™ PRO W7000 Series Graphics Products, AMD Instinct™ MI250, AMD Instinct™ MI210, AMD Instinct™ MI300X, AMD Instinct™ MI325X, AMD Instinct™ MI308X, AMD Instinct™ MI300A, AMD Radeon™ PRO V520, AMD Radeon™ PRO V620, AMD Radeon™ PRO V710
Vulnerable Versions:
AMD Software: Adrenalin Edition 25.12.1 (25.10.37.01), AMD Software: Adrenalin Edition 25.11.1 (25.20.29.01), AMD Software: PRO Edition 25.Q4 (25.10.37.01), AMD Software: PRO Edition 25.Q3.1 (25.10.32), ROCm 7.0, ROCm 6.3.1, ROCm 6.4.2, BKC 26 (ROCm 7.0.1), Contact your AMD Customer Engineering representative

Timeline

Official Publish: May 15th, 2026
Last Modified: May 15th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)