Improper Access Control in AMD Secure Encrypted Virtualization Firmware
CVE-2025-29948
Key Information:
- Vendor
Amd
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2025-29948?
The AMD Secure Encrypted Virtualization (SEV) firmware has a vulnerability that stems from improper access control mechanisms. This issue could allow a malicious hypervisor to circumvent the RMP (Runtime Memory Protection) safeguards, leading to possible compromise of the integrity of SEV-SNP guest memory. Such unauthorized access poses significant risks to the security and privacy of virtualized environments, necessitating prompt attention to patch the affected firmware and mitigate potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AMD EPYC™ 9005 Series Processors TurinPI 1.0.0.6
AMD EPYC™ Embedded 9005 Series Processors EmbTurinPI-SP5_1.0.0.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved