---
id: CVE-2025-29933
title: >-
  Improper input validation within AMD uProf can allow a local attacker to write
  out of bounds, potentially resulting in a crash or denial of service
summary: >-
  Improper input validation within AMD uProf can allow a local attacker to write
  out of bounds, potentially resulting in a crash or denial of service
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-787
vendor: amd
product: uprof
affected:
  - uprof < 5.1.576
  - uprof < 5.1.663
  - uprof < 5.1.701
patched:
  - uprof 5.1.701
published: '2025-11-24'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-29933'
references:
  - url: >-
      https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-9019.html
    label: psirt@amd.com
tags:
  - nvd
epss: 0.0011
epssPercentile: 0.01196
ingestedAt: '2026-09-30T23:29:32.475Z'
---

## Overview

Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service

## Affected

- `uprof < 5.1.576`
- `uprof < 5.1.663`
- `uprof < 5.1.701`

## Remediation

Upgrade past the affected range:

- `uprof 5.1.701`
