AMD EPYC and Embedded EPYC Processors IOMMU Write Buffer Vulnerability Allowing Out-of-Bounds Conditions

Vulnerability

A vulnerability exists in AMD EPYC 7003 and 9004 series processors, as well as in AMD EPYC 7003 and 9004 embedded series processors. Insufficient checks of the RMP on host buffer access in IOMMU may enable an attacker with privileges and a compromised hypervisor to trigger an out-of-bounds condition, potentially leading to a loss of confidential guest integrity.

Impact

Exploitation of this vulnerability could result in unauthorized data modification, specifically writing data outside the intended buffer limits, which could compromise the integrity of confidential guest data in SNP environments.

Remediation

Users are advised to update to the SEV firmware versions specified for their processor series, along with an operating system-specific update. For AMD EPYC 7003 and 9004 embedded series processors, the SEV firmware update must be combined with an OS update. Consult the AMD product security bulletin AMD-SB-3016 for detailed guidance.

Added: Apr 16, 2026, 7:37 PM
Updated: Apr 16, 2026, 7:37 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
1.7
exploitability
2.3
remediation
7.7
relevance
6.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.