CVE-2026-0466: Medium severity AMD uProf vulnerability
Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
AMD uProffrom your environment.Uninstall AMD uProf from systems where it is not required to eliminate the risk of local users being able to write to kernel-shared memory.
- Configuration
Restrict access to uProf binaries and kernel components so only privileged administrators can execute them. Change filesystem permissions, remove execute bit for non-privileged users, and enforce OS-level policies to prevent unprivileged users from running uProf or accessing the kernel-shared memory interfaces.
AMD uProf access permissions / execution privilege = restrict to privileged users (root/administrators) - Compensating control
Apply host-based mitigations to reduce exposure: enforce least-privilege for local accounts, disable or remove unnecessary local user accounts, and use OS sandboxing/mandatory access control (e.g., SELinux or AppArmor) to block unprivileged processes from accessing kernel-shared memory until a vendor patch is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0466?
The severity of CVE-2026-0466 is medium, rated at 6.8 on the CVSS scale.
How do I fix CVE-2026-0466?
To fix CVE-2026-0466, apply the latest updates or patches provided by AMD for the uProf software.
What type of access does CVE-2026-0466 exploit?
CVE-2026-0466 exploits improper access control that allows local attackers with user privileges to write to kernel-shared memory.
What are the potential impacts of CVE-2026-0466?
The potential impacts of CVE-2026-0466 include system crashes and denial of service.
Who is affected by CVE-2026-0466?
Users of AMD uProf software may be affected by CVE-2026-0466.