GPU VulnDB

Database/Firmware, BMC & network fabric

AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmware: MULTI-TENANT ISOLATION: The PMU firmware

CVE-2025-0038Firmware, BMC & network fabriccurated

Impact

MULTI-TENANT ISOLATION: The PMU firmware on Zynq UltraScale+ devices does not validate addresses when executing Configuration Security Unit runtime services, giving access to isolated or protected memory. Companion to the Versal PLM issue and the same shape: the firmware component that enforces isolation on the device can be steered outside its own boundaries.

Who can reach it

Local to the device, via CSU runtime service calls through the PMU firmware.

What to do

Fixed in updated PMU firmware from AMD/Xilinx. Device firmware update plus card reset, gated on your card integrator shipping it.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.