Improper Memory Access Vulnerability in AMD Products
CVE-2023-31351
5.3MEDIUM
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 6 September 2025
What is CVE-2023-31351?
The vulnerability arises from improper restrictions in the Input-Output Memory Management Unit (IOMMU) which could enable a malicious hypervisor to gain unauthorized access to sensitive guest memory. This flaw poses a significant threat to the integrity and confidentiality of the virtualized environments, allowing attackers to manipulate guest operations and potentially extract sensitive data. Users of AMD IOMMU should take precautions and monitor for updates to mitigate the risk.
Affected Version(s)
AMD EPYC™ 7003 Series Processors Milan 100C
AMD EPYC™ 8004 Series Processors Genoa 100C
AMD EPYC™ 9004 Series Processors Genoa 100C