PT-2026-106366 · Amd · Rccl

CVE-2026-43598

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AMD ROCm Communication Collectives Library (RCCL) versions prior to 7.14
Description Improper input validation in the ROCm Communication Collectives Library (RCCL) allows a compromised peer rank or network-adjacent attacker to dereference an attacker-controlled pointer. This flaw can lead to remote code execution on Instinct GPUs.
Recommendations Update to ROCm 7.14.

Fix

RCE

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43598

Affected Products

Rccl