CVE-2026-43598: CWE-822 Untrusted Pointer Dereference in AMD AMD Instinct™ MI210
Description
CVE-2026-43598 is a high-severity vulnerability in the AMD ROCm Communication Collectives Library (RCCL) used by AMD Instinct™ MI210. It involves improper input validation that could allow a compromised peer rank or a network-adjacent attacker to dereference an attacker-controlled pointer. This flaw could potentially lead to remote code execution. The vulnerability has a CVSS 4.0 score of 7.7, indicating significant impact but requiring high attack complexity and limited privileges. No patch or remediation information is currently available.
CVSS v4.0
Score 7.7high
Affected software
AMD
AMD Instinct™ MI210
AMD
AMD Instinct™ MI250
AMD
AMD Instinct™ MI300A
AMD
AMD Instinct™ MI300X
AMD
AMD Instinct™ MI325X
AMD
AMD Instinct™ MI350X
AMD
AMD Instinct™ MI355X
AMD
AMD Instinct™ MI308X
AMD
AMD Instinct™ MI250X
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-43598) is due to improper input validation in the AMD ROCm Communication Collectives Library (RCCL) component of AMD Instinct™ MI210. An attacker who controls a peer rank or is adjacent on the network could exploit this flaw to dereference a pointer controlled by the attacker, which may lead to remote code execution. The CVSS 4.0 vector indicates network attack vector, high attack complexity, low privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. There is no vendor advisory or patch information provided at this time.
Potential Impact
Successful exploitation could allow an attacker with limited privileges and network adjacency to execute arbitrary code remotely on the affected system. This could compromise system confidentiality, integrity, and availability. However, exploitation requires a high level of complexity and specific conditions such as control over a peer rank or network adjacency.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or workaround information is currently available. Monitor AMD's advisories for updates and apply patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- AMD
- Date Reserved
- 2026-05-01T18:15:55.867Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac55b392cdf04f656dc2ad9
Added to database: 10/06/2026, 20:34:01 UTC
Last enriched: 10/06/2026, 20:48:11 UTC
Last updated: 10/06/2026, 20:49:08 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.