Description: Researchers from ETHz reported that a malicious hypervisor could corrupt the Reverse Map Table (RMP) during Secure Nested Paging (SNP) initialization.
AMD reproduced the issue and determined it is due to a race condition that can occur while the AMD Secure Processor (ASP) is initializing the RMP. This attack could allow a malicious hypervisor to manipulate the initial RMP content, potentially resulting in loss of SEV-SNP guest memory integrity. AMD has released mitigations for this vulnerability.
AMD-SB-3020
CVE-2025-0033
Affected Platforms and BIOS version numbers that contain the fix Details
2025-08-12
AMD Embedded Vulnerabilities – August 2025, Aug. 12, 2025
Description: Potential vulnerabilities in AMD Embedded processors were reported, and mitigations are being provided through Platform Initialization (PI) firmware packages.
AMD-SB-5007
CVE-2023-20540
CVE-2023-31326
CVE-2021-46750
CVE-2024-36331
CVE-2024-21977
CVE-2025-0011
CVE-2021-26377
CVE-2024-21970
CVE-2023-20572
CVE-2024-21965
CVE-2023-31351
CVE-2025-0009
CVE-2025-0032
CVE-2024-36354
CVE-2024-21947
CVE-2021-26383
CVE-2024-36352
CVE-2024-36342
CVE-2021-46757
Affected Platforms and BIOS version numbers that contain the fix Details
2025-08-12
AMD Server Vulnerabilities – August 2025, Aug. 12, 2025
Description: Potential vulnerabilities in AMD EPYC™ Processor platforms that affect IOMMU, AMD Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP) and other platform components, were found during audits performed internally and by third parties.
Mitigations have been provided in AMD EPYC™ Platform Initialization (PI) firmware packages.
AMD-SB-3014
CVE-2024-36331
CVE-2024-21977
CVE-2024-21965
CVE-2023-31351
CVE-2025-0032
CVE-2024-36354
Affected Platforms and BIOS version numbers that contain the fix Details
2025-07-08
AMD Transient Scheduler Attacks, July 08, 2025
Description: AMD discovered several transient scheduler attacks related to the execution timing of instructions under specific microarchitectural conditions while investigating a Microsoft® report titled “Enter, Exit, Page Fault, Leak: Testing Isolation Boundaries for Microarchitectural Leaks”.
AMD has debugged these patterns and identified a speculative side channel affecting AMD CPUs . In some cases, an attacker may be able to use this timing information to infer data from other contexts, resulting in information leakage.
AMD-SB-7029
CVE-2024-36349
CVE-2024-36348
CVE-2024-36357
CVE-2024-36350
Affected Platforms and BIOS version numbers that contain the fix Details
2025-07-01
Zynq™ UltraScale+™ SoC Overwriting Protected Memory Regions Through PMU Firmware, July 01, 2025
Description: In Zynq™ UltraScale+™ devices, the Platform Management Unit (PMU) Firmware is designed to implement runtime (post boot) software services that allow a remote processor to command the PMU to execute cryptographic operations (i.e. AES-GCM/256, SHA3-284, RSA) using the hardened crypto accelerators, programmable logic readback, and eFUSE read and write operations within the Configuration Security Unit (CSU).
The researcher’s paper describes a vulnerability that exists with commanding these runtime services, in that the memory pointers passed with the command are not checked to verify that the requesting processor has access to the memory space.
AMD-SB-8008
CVE-2025-0038
Affected Platforms and BIOS version numbers that contain the fix Details
2025-06-23
Uninitialized GPU Register Access, Jun 23, 2025
Description: AMD is aware of a publicly available paper titled “Whispering Pixels: Exploiting Uninitialized Register Accesses in Modern GPUs” which describes a technique for potentially leaking pixel data from GPU registers.ks remain applicable to mitigate the techniques described in the researchers’ summary.
AMD-SB-6013
CVE-2024-21969
2025-06-23
GPU Memory Leaks, Jun 23, 2025
Description: Researchers from Trail of Bits reported a potential vulnerability, titled “LeftoverLocals.” According to their research, a compromised GPU kernel could potentially read local memory values from another kernel.
Affected Platforms and BIOS version numbers that contain the fix Details
2025-06-10
Unauthorized Access to AMD Secure Processor’s Crypto-Co-Processor, Jun 10, 2025
Description: A security researcher has reported to AMD a potential vulnerability which could allow a privileged attacker to access the Crypto Co-Processor (CCP) registers from the x86 architecture.
AMD-SB-7039
CVE-2023-20599
Affected Platforms and BIOS version numbers that contain the fix Details