Memory Integrity Flaw in AMD Secure Encrypted Virtualization Firmware
CVE-2025-29952

5.9MEDIUM

What is CVE-2025-29952?

A vulnerability exists in the AMD Secure Encrypted Virtualization firmware due to improper initialization practices. This flaw can be exploited by an attacker with administrative privileges to corrupt memory protected by RMP, potentially compromising the integrity of guest memory and leading to unauthorized data access or modification.

Affected Version(s)

AMD EPYC™ 9005 Series Processors TurinPI 1.0.0.6

AMD EPYC™ Embedded 9005 Series Processors EmbTurinPI-SP5_1.0.0.1

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.