Home

Description

A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity.

PUBLISHED Reserved 2024-11-21 | Published 2026-02-10 | Updated 2026-02-11 | Assigner AMD




MEDIUM: 4.6CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

Problem types

CWE-416 Use After Free

Product status

Default status
affected

GenoaPI 1.0.0.G
unaffected

Default status
affected

MilanPI 1.0.0.H
unaffected

Default status
affected

TurinPI 1.0.0.5
unaffected

Default status
affected

GenoaPI 1.0.0.G
unaffected

Default status
affected

EmbMilanPI-SP3 v9 1.0.0.C
unaffected

Default status
affected

EmbGenoaPI-SP5 1.0.0.B
unaffected

Default status
affected

EmbTurinPI-SP5_1.0.0.1
unaffected

Default status
affected

EmbGenoaPI-SP5 1.0.0.B
unaffected

Default status
affected

EmbGenoaPI-SP5 1.0.0.B
unaffected

References

www.amd.com/...es/product-security/bulletin/AMD-SB-3023.html

cve.org (CVE-2025-0031)

nvd.nist.gov (CVE-2025-0031)

Download JSON