AMD KMD double-free, privileged attacker can achieve arbitrary code exec
CVE-2023-20511 Published on August 31, 2026
Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.
Weakness Type
Release of Invalid Pointer or Reference
The application attempts to return a memory resource to the system, but calls the wrong release function or calls the appropriate release function incorrectly.
Affected Versions
AMD Radeon™ Instinct™ MI25 Graphics Products:- Version Contact your AMD Customer Engineering representative is unaffected.
- Version Contact your AMD Customer Engineering representative is unaffected.
Exploit Probability
EPSS
0.23%
Percentile
12.73%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.