Home

Description

Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity.

PUBLISHED Reserved 2022-10-27 | Published 2026-04-16 | Updated 2026-04-16 | Assigner AMD




MEDIUM: 5.6CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-788 Access of Memory Location After End of Buffer

Product status

Default status
affected

SEV FW 1.37.23
unaffected

Default status
affected

SEV FW 1.37.31
unaffected

Default status
affected

EmbMilanPI-SP3 1.0.0.B
unaffected

Default status
affected

EmbGenoaPI-1.0.0.A
unaffected

References

www.amd.com/...es/product-security/bulletin/AMD-SB-3016.html

cve.org (CVE-2023-20585)

nvd.nist.gov (CVE-2023-20585)

Download JSON