Insufficient Data Removal in SEV Firmware Affects AMD Products
CVE-2025-29946

4.5MEDIUM

What is CVE-2025-29946?

The vulnerability arises from insufficient data removal within the SEV firmware, where the IOMMU does not fully flush, leaving guest memory susceptible to potential exposure. This could lead to unauthorized disclosure of sensitive information and compromise of system integrity, heightening the risks for environments relying on hardware virtualization. Users of affected AMD products should review their firmware configurations and mitigate risks associated with this condition.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

AMD EPYC™ 9005 Series Processors TurinPI 1.0.0.6

AMD EPYC™ Embedded 9005 Series Processors EmbTurinPI-SP5_1.0.0.1

References

CVSS V4

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.