Improper Handling of Nested Page Table Entries in AMD Products
CVE-2023-20582

5.3MEDIUM

Key Information:

Vendor
Amd
Vendor
CVE Published:
11 February 2025

Summary

An improper handling of invalid nested page table entries in AMD's IOMMU could allow an attacker with privileged access to induce faults in page table entries, potentially circumventing RMP checks within the Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) framework. This flaw poses serious risks to the integrity of guest memory, potentially affecting the security of virtualized environments.

Affected Version(s)

AMD EPYC™ 9004 Processors GenoaPI 1.0.0.C

AMD EPYC™ Embedded 9004 EmbGenoaPI-SP5 1.0.0.7

AMD EPYC™ 9004 Processors GenoaPI 1.0.0.C

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.