CVE-2025-29948
Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory integrity.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N
- EPSS probability
- 0.14%
- CWE
- CWE-1260
- Published
- 2026-02-10
- Last modified
- 2026-03-13
Affected products
- AMD AMD EPYC™ 9005 Series Processors
- AMD AMD EPYC™ Embedded 9005 Series Processors
Weakness type
Related vulnerabilities
- CVE-2025-31936 — Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors...
- CVE-2026-20760 — Improper handling of overlap between protected memory ranges in some microcode for some Intel(R)...
- CVE-2018-25240 — Watchr 1.1.0.0 Denial of Service via Search
- CVE-2018-25238 — VSCO 1.1.1.0 Denial of Service via Search
- CVE-2019-25602 — GSearch 1.0.1.0 Denial of Service via Search Input
- CVE-2019-25592 — PHPRunner 10.1 Denial of Service via Dashboard Name Field
- CVE-2019-25585 — Deluge 1.3.15 Denial of Service via Webseeds Field
- CVE-2019-25572 — NordVPN 6.19.6 Denial of Service via Email Field Buffer Overflow