Do not open a public GitHub issue for a suspected security vulnerability.
Report the issue privately through the AMD Product Security portal. Include a description of the issue and its impact, steps to reproduce it, and affected versions or commits.
This policy covers code and configuration in this repository. Report vulnerabilities in third-party dependencies to their upstream maintainers as well. For AMD product issues unrelated to this repository, use the AMD Product Security portal.