CVE-2025-29946
Awaiting Analysis
Awaiting Analysis - Queue
BaseFortify
Publication date: 2026-02-10
Last updated on: 2026-02-10
Assigner: Advanced Micro Devices Inc.
Description
Description
Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amd | epyc | From 1.37.2A (inc) to 1.37.31 (inc) |
| amd | genoa | * |
| amd | embedded_9004 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1301 | The product's data removal process does not completely delete all data and potentially sensitive information within hardware components. |