CVE-2025-29946
Awaiting Analysis Awaiting Analysis - Queue
BaseFortify

Publication date: 2026-02-10

Last updated on: 2026-02-10

Assigner: Advanced Micro Devices Inc.

Description
Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-10
Last Modified
2026-02-10
Generated
2026-05-27
AI Q&A
2026-02-10
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
amd epyc From 1.37.2A (inc) to 1.37.31 (inc)
amd genoa *
amd embedded_9004 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1301 The product's data removal process does not completely delete all data and potentially sensitive information within hardware components.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves insufficient or incomplete data removal in a hardware component within the SEV firmware. Specifically, the firmware does not fully flush the IOMMU (Input-Output Memory Management Unit), which is responsible for managing memory access. As a result, sensitive data in guest memory may not be properly cleared.

Because the IOMMU is not fully flushed, there is a risk that confidential or integrity-sensitive information could be exposed or compromised.


How can this vulnerability impact me? :

This vulnerability can lead to a loss of confidentiality and integrity in guest memory. In practical terms, this means that sensitive data stored in virtualized environments using SEV firmware could potentially be accessed or tampered with by unauthorized parties.

Such exposure could result in data breaches, unauthorized data disclosure, or manipulation of critical information within the affected systems.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

I don't know


How can this vulnerability be detected on my network or system? Can you suggest some commands?

I don't know


What immediate steps should I take to mitigate this vulnerability?

I don't know


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart