AMD TEE SOC Driver: Bad Param Sanitization in DRV_SOC_CMD_ID_SRIOV
CVE-2025-66660 Published on May 15, 2026
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cause incorrect shared memory mapping, potentially resulting in unexpected behavior.
Vulnerability Analysis
CVE-2025-66660 is exploitable with local system access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Affected Versions
AMD Radeon™ RX 6000 Series Graphics Products:- Version AMD Software: Adrenalin Edition 25.12.1 (25.10.37.01) is unaffected.
- Version AMD Software: Adrenalin Edition 25.11.1 (25.20.29.01) is unaffected.
- Version AMD Software: PRO Edition 25.Q4 (25.10.37.01) is unaffected.
- Version AMD Software: PRO Edition 25.Q3.1 (25.10.32) is unaffected.
- Version ROCm 7.0.1 is unaffected.
- Version ROCm 7.0.1 is unaffected.
- Version BKC 26 is unaffected.
- Version ROCm 6.3 is unaffected.
- Version ROCm 6.3 is unaffected.
- Version ROCm 6.4.2 is unaffected.
- Version Contact your AMD Customer Engineering representative is unaffected.
- Version Contact your AMD Customer Engineering representative is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.