Description
Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected products
- AMD / AMD EPYC™ 7003 ProcessorsMilanPI 1.0.0.C – MilanPI 1.0.0.C
- AMD / AMD EPYC™ 9004 ProcessorsGenoaPI 1.0.0.B – GenoaPI 1.0.0.B
- AMD / AMD EPYC™ Embedded 7003"EmbMilanPI-SP3 1.0.0.8" – "EmbMilanPI-SP3 1.0.0.8"
- AMD / AMD EPYC™ Embedded 9004EmbGenoaPI-SP5 1.0.0.6 – EmbGenoaPI-SP5 1.0.0.6