Insufficient Data Removal in SEV Firmware Affects AMD Products
CVE-2025-29946
4.5MEDIUM
Key Information:
- Vendor
Amd
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2025-29946?
The vulnerability arises from insufficient data removal within the SEV firmware, where the IOMMU does not fully flush, leaving guest memory susceptible to potential exposure. This could lead to unauthorized disclosure of sensitive information and compromise of system integrity, heightening the risks for environments relying on hardware virtualization. Users of affected AMD products should review their firmware configurations and mitigate risks associated with this condition.
Affected Version(s)
AMD EPYC™ 9005 Series Processors TurinPI 1.0.0.6
AMD EPYC™ Embedded 9005 Series Processors EmbTurinPI-SP5_1.0.0.1