CVE-2025-62863Critical· 9.8▾ MidnightAmpere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM PCIe driver that could result in an out-of-bounds write within PC…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM PCIe driver that could result in an out-of-bounds write within PCIe driver’s S-EL0 address space.
ampereone_a192-32m_firmware < 5.4.5.1ampereone_a192-26m_firmware < 5.4.5.1ampereone_a160-28m_firmware < 5.4.5.1ampereone_a144-33m_firmware < 5.4.5.1ampereone_a144-26m_firmware < 5.4.5.1ampereone_a96-36m_firmware < 5.4.5.1ampereone_a96-36x_firmware < 4.4.5.2ampereone_a128-34x_firmware < 4.4.5.2ampereone_a144-24x_firmware < 4.4.5.2ampereone_a144-27x_firmware < 4.4.5.2ampereone_a160-28x_firmware < 4.4.5.2ampereone_a192-26x_firmware < 4.4.5.2ampereone_a192-26x_firmware < 3.5.9.3ampereone_a192-32x_firmware < 3.5.9.3Upgrade past the affected range:
ampereone_a192-32m_firmware 5.4.5.1ampereone_a192-26m_firmware 5.4.5.1ampereone_a160-28m_firmware 5.4.5.1ampereone_a144-33m_firmware 5.4.5.1ampereone_a144-26m_firmware 5.4.5.1ampereone_a96-36m_firmware 5.4.5.1ampereone_a96-36x_firmware 4.4.5.2ampereone_a128-34x_firmware 4.4.5.2ampereone_a144-24x_firmware 4.4.5.2ampereone_a144-27x_firmware 4.4.5.2ampereone_a160-28x_firmware 4.4.5.2ampereone_a192-26x_firmware 3.5.9.3ampereone_a192-32x_firmware 3.5.9.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62864Critical· 9.8Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM MMCommunicate service that could result in an out-of-bounds write…
CVE-2022-48423High· 7.8In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names
CVE-2022-0995High· 7.8An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem
CVE-2021-4090High· 7.1An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel
CVE-2020-1054High· 7.0An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory
CVE-2023-29551High· 8.8Memory safety bugs present in Firefox 111