System Management Mode Vulnerability in AMD Products
CVE-2026-0438

5.4MEDIUM

What is CVE-2026-0438?

A vulnerability exists in the System Management Mode (SMM) of AMD processors that allows an attacker with high privileges to execute code from non-SMM memory. This scenario requires user interaction and specific preconditions, which increases the complexity of exploitation. If successful, an attacker could gain unauthorized access to system resources, undermining the confidentiality, integrity, and availability of the affected systems. Users of AMD processors should be aware of these risks and take necessary precautions.

Affected Version(s)

AMD EPYC™ 4004 Series Processors ComboAM5PI 1.0.0.d / ComboAM5PI 1.1.0.3f / ComboAM5PI_1.2.0.3i

AMD EPYC™ 4005 Series Processors ComboAM5PI_1.2.0.3i

AMD Ryzen™ 7000 Series Desktop Processors ComboAM5PI 1.0.0.d

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.