securityonline.info 6 Oct 2026, 00:35 UTC

AMD fixes high risk code execution flaw in RCCL GPU library

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

AMD has disclosed a remote-code-execution risk in its ROCm ROCm RCCL (RCCL) library, tracked as CVE-2026-43598, with a CVSS score of 7.7. The flaw resides in the RCCL proxy communication path and stems from insufficient validation of attacker-controlled data. AMD states a compromised peer could potentially dereference an attacker-controlled pointer, disclose memory contents and bypass ASLR, allowing code to run in the RCCL process context.

The company notes that exploitation would be highly dependent on the attack surface and is described as having high attack complexity in its CVSS assessment. The vulnerability has been fixed in ROCm 7.14, released on 15 July 2026.

Affected hardware includes AMD Instinct accelerators: MI210, MI250 and MI250X; MI300A, MI300X and MI308X; and MI325X, MI350X and MI355X. AMD credits researcher Luna Nova with the report. At present, the article indicates no exploitation in the wild or publicly available PoCs. Mitigation recommended by AMD is to upgrade all nodes in the cluster to ROCm 7.14 or newer and to keep RCCL traffic within isolated, trusted networks. Organisations should assess their exposure because CVSS scores can vary by implementation.

In practice, this means applying the patch across the whole multi-node GPU cluster and reviewing network segmentation around RCCL communications to reduce the risk of a compromised peer affecting other nodes.

View full article

Article by CyberSIXT