Home

Description

Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secure nested paging (SNP) initialization, potentially resulting in a loss of guest memory confidentiality and integrity.

PUBLISHED Reserved 2025-03-12 | Published 2026-02-10 | Updated 2026-02-10 | Assigner AMD




MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N

Problem types

CWE-284 Improper Access Control

Product status

Default status
affected

GenoaPI 1.0.0.G
unaffected

Default status
affected

MilanPI 1.0.0.H
unaffected

Default status
affected

TurinPI 1.0.0.6
unaffected

Default status
affected

GenoaPI 1.0.0.G
unaffected

Default status
affected

EmbMilanPI-SP3 v9 1.0.0.C
unaffected

Default status
affected

EmbGenoaPI-SP5 1.0.0.B
unaffected

Default status
affected

EmbTurinPI-SP5_1.0.0.1
unaffected

Default status
affected

EmbGenoaPI-SP5 1.0.0.B
unaffected

Default status
affected

EmbGenoaPI-SP5 1.0.0.B
unaffected

References

www.amd.com/...es/product-security/bulletin/AMD-SB-3023.html

cve.org (CVE-2025-29939)

nvd.nist.gov (CVE-2025-29939)

Download JSON