---
id: CVE-2026-0482
title: >-
  In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot
  mode—when enabled through board modifications—could allow crafted images to
  trigger a buffer overflow and overwrite an active function pointer, which may
  resul…
summary: >-
  In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot
  mode—when enabled through board modifications—could allow crafted images to
  trigger a buffer overflow and overwrite an active function pointer, which may
  resul…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'
cwe:
  - CWE-787
vendor: AMD
product: Alveo™ Accelerator Cards
affected:
  - alveo_accelerator_cards (all versions)
  - versal_prime_series_adaptive_socs (all versions)
  - versal_premium_series_adaptive_socs (all versions)
  - versal_ai_edge_series_adaptive_socs (all versions)
  - versal_ai_core_series_adaptive_socs (all versions)
  - versal_hbm_series_adaptive_socs (all versions)
  - versal_rf_series_adaptive_socs (all versions)
  - >-
    versal_premium_series_gen_2_adaptive_socs_2vp3402_2vp3502_2vp3602 (all
    versions)
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T22:16:56.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0482'
references:
  - url: >-
      https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-8028.html
    label: psirt@amd.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-05T22:35:24.734Z'
---

## Overview

In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled through board modifications—could allow crafted images to trigger a buffer overflow and overwrite an active function pointer, which may result in arbitrary code execution during boot process. This condition could lead to potential impacts on confidentiality, integrity, and availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
