CVE-2025-29946
BaseFortify
Publication date: 2026-02-10
Last updated on: 2026-02-10
Assigner: Advanced Micro Devices Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amd | epyc | From 1.37.2A (inc) to 1.37.31 (inc) |
| amd | genoa | * |
| amd | embedded_9004 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1301 | The product's data removal process does not completely delete all data and potentially sensitive information within hardware components. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves insufficient or incomplete data removal in a hardware component within the SEV firmware. Specifically, the firmware does not fully flush the IOMMU (Input-Output Memory Management Unit), which is responsible for managing memory access. As a result, sensitive data in guest memory may not be properly cleared.
Because the IOMMU is not fully flushed, there is a risk that confidential or integrity-sensitive information could be exposed or compromised.
How can this vulnerability impact me? :
This vulnerability can lead to a loss of confidentiality and integrity in guest memory. In practical terms, this means that sensitive data stored in virtualized environments using SEV firmware could potentially be accessed or tampered with by unauthorized parties.
Such exposure could result in data breaches, unauthorized data disclosure, or manipulation of critical information within the affected systems.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
I don't know
How can this vulnerability be detected on my network or system? Can you suggest some commands?
I don't know
What immediate steps should I take to mitigate this vulnerability?
I don't know