Memory Corruption Vulnerability in AMD Platform Management Framework
CVE-2025-29938

7.1HIGH

What is CVE-2025-29938?

The AMD Platform Management Framework (PMF) contains a memory corruption vulnerability due to an unchecked return value. This flaw could potentially allow an attacker to manipulate memory, leading to denial of service or arbitrary code execution. Implementing robust input validation safeguards against such vulnerabilities is critical for maintaining system security.

Affected Version(s)

AMD Ryzen Embedded 8000 Series Processors AMD Ryzen™ Chipset Driver 7.06.02.123

AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt R") 7.06.02.123

AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Phoenix") 7.06.02.123

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported through AMD Bug Bounty Program
.