CVE-2025-62863: Critical severity Ampere AmpereOne AC03 vulnerability
Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM PCIe driver that could result in an out-of-bounds write within PCIe driver’s S-EL0 address space.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62863?
CVE-2025-62863 has been classified as a high-severity vulnerability due to the potential for an out-of-bounds write in the PCIe driver.
How do I fix CVE-2025-62863?
To fix CVE-2025-62863, upgrade the affected Ampere devices to the latest versions: AC03 to 3.5.9.3, AC04 to 4.4.5.2, and AmpereOne M to 5.4.5.1.
Which devices are affected by CVE-2025-62863?
The affected devices include AmpereOne AC03, AmpereOne AC04, and AmpereOne M, all prior to their respective patched versions.
What type of vulnerability is CVE-2025-62863?
CVE-2025-62863 is a vulnerability involving an incorrectly formed SMC call leading to potential memory corruption in the PCIe driver's S-EL0 address space.
What could happen if CVE-2025-62863 is exploited?
Exploitation of CVE-2025-62863 could lead to unauthorized memory access or system instability due to an out-of-bounds write.