Image: AMD
TL;DR
AMD has disclosed CVE-2026-43598, an AMD RCCL vulnerability rated 7.7 on CVSS 4.0. The flaw sits in the ROCm Communication Collectives Library and could let a compromised peer run code remotely. AMD fixed it in ROCm 7.14, released on July 15, 2026.
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy It Matters
RCCL handles communication between GPUs in multi-node clusters. These clusters often run large AI training jobs on AMD Instinct accelerators. As a result, one bad node could threaten others in the same job. A flaw in the ROCm Communication Collectives Library therefore reaches the core of shared GPU infrastructure.
AMD credits researcher Luna Nova with the report. So far, no exploitation in the wild or public proof-of-concept has been confirmed.
How the Attack Works
The bug lives in the RCCL proxy communication path. According to AMD, “insufficient validation of attacker-controlled data within the RCCL proxy communication path” lets a remote attacker “disclose memory contents and bypass ASLR protections.”
From there, AMD says the flaw could allow “a compromised peer rank or network-adjacent attacker to dereference an attacker-controlled pointer, potentially resulting in remote code execution.” The code would run in the context of the RCCL process. However, the high attack complexity in its CVSS score makes exploitation harder.
Affected Versions
The AMD RCCL vulnerability affects these AMD Instinct accelerators:
- MI210, MI250 and MI250X
- MI300A, MI300X and MI308X
- MI325X, MI350X and MI355X
Patch and Mitigation Steps
Upgrade to ROCm 7.14 or later on every node in the cluster. AMD also notes that “specific CVSS scores may change subject to your implementation.” Therefore, teams should assess their own exposure. In addition, keep RCCL traffic on isolated, trusted networks.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!