-
CVE-2025-0037: About AMD Versal™ Adaptive SoC – Initial publication 2025-06-03
(9th June 2025) Preface: AMD’s Versal™ Adaptive SoCs are used in a wide range of industries, particularly those requiring high-performance, low-latency processing and flexibility, such as data centers, wireless networking, automotive, aerospace, and defense. Versal chips are also utilized in areas like 5G wireless, advanced driver assist, and even 3D printing. AMD’s Versal™ Adaptive SoC…
-
CVE-2025-1246: A non-privileged user process can perform valid GPU processing operations (8th June 2025)
Preface: The Valhall family of Mali GPUs uses the same top-level architecture as the previous generation Bifrost GPUs. The Valhall family uses a unified shader core architecture. Arm’s 5th generation GPU architecture, on the other hand, is a type of GPU architecture that is designed for visual computing, especially on mobile devices, and includes features…
-
CVE-2024-53010 – Improper Access Control in Core (5th Jun 2025)
Preface: Android HLOS – -Runs on the Application Processor (main CPU) -Main Android OS (Linux kernel, system services, apps) Background: The Snapdragon 8 application processor (including variants like Snapdragon 8 Gen 3 and Snapdragon 8 Elite) uses the Adreno GPU. The Adreno GPU is a core component of Qualcomm’s Snapdragon mobile platforms and is responsible…
-
CVE-2025-0036: A potential vulnerability exists with the configuration of the SSS (Secure Stream Switch) – 5th Jun 2025
Preface: AMD’s Versal Adaptive SoCs are designed for high-performance computing, offering a blend of programmable logic, processing system, and AI engines, along with advanced memory and interfaces. They excel in cloud, network, and edge applications by combining heterogeneous compute with a wide range of hard IP. This architecture enables outstanding performance/watt and adapts to changing…
-
Cache-based Side-Channel Attack Against SEV (4th Jun 2025)
Originally posted by AMD 3rd Feb 2025 2025-02-17 – Updated Acknowledgement 2025-06-03 Update:A subsequent report of the same attacks was received from researchers at Graz University of Technology. Preface: FIPS 186-5 removes DSA as an approved digital signature algorithm “due to a lack of use by industry and based on academic analyses that observed that…
-
CVE-2025-27029 – Buffer Over-read in WLAN HAL (3rd Jun 2025)
Preface: Google has been transitioning HALs from HIDL to AIDL since Android 11, and by Android 13 and 14, most major HALs—including Wi-Fi (WLAN), Audio, Bluetooth, and Telephony—have adopted AIDL as the standard interface definition language. Background: In Android, defining and managing buffers in the WAN HAL (Wide Area Network Hardware Abstraction Layer) isn’t a…
-
CVE-2025-21479: Incorrect Authorization in Graphics (2nd June 2025)
Preface: Snapdragon chipsets, which are a type of System-on-a-Chip (SoC), often include memory components, such as RAM (Random Access Memory) and ROM (Read-Only Memory), within the chip itself. This integrated approach allows for faster and more efficient data processing within the device. Background: In Qualcomm Snapdragon SoCs, the Adreno GPU is responsible for graphics and…
-
CVE-2025-1763: About GitLab EE (2nd Jun 2025)
Preface: The computer industry favors GitLab because it provides a comprehensive, integrated software development platform that covers everything from planning and code management to continuous integration and deployment. This “full operation and maintenance” approach simplifies the software development life cycle and promotes collaboration between different teams. GitLab’s open source nature, free basic version, and strong…
-
The relationship between humans and water in the Old Testament (30-05-2025)
Preface: Humans need water to survive. Water is a basic need for life and an important component of the human body. On the other hand, Massive floods have occurred multiple times in Earth’s history, some of which are significant geological events that have shaped the landscape and influenced the course of life on Earth. Examples…
-
Deserialization of Untrusted Data vulnerability in Apache InLong (29-05-2025)
Preface: Apache InLong can be a valuable component in machine learning (ML) and artificial intelligence (AI) workflows, particularly in the data engineering and streaming data pipeline stages. Background: Apache InLong is a one-stop massive data integration framework that provides automatic, secure, reliable and high-performance data transmission capabilities. It also supports batch and streaming, making it…