AMD EPYC and Ryzen Embedded Processors IOMMU Vulnerability Allowing Memory Access by Hypervisor

Vulnerability

A vulnerability has been identified in the IOMMU of AMD EPYC and Ryzen Embedded processors. This vulnerability improperly restricts operations, which could enable a malicious hypervisor to access private memory of guests, leading to a loss of integrity. Affected processors include the AMD EPYC 7003 and 9004 series, as well as various Ryzen Embedded series processors. The issue arises from inadequate operation restrictions in the IOMMU, potentially allowing hypervisors to manipulate or access guest memory inappropriately.

Impact

Exploitation of this vulnerability could allow a hypervisor to access and manipulate guest private memory, resulting in a loss of integrity for the affected virtual machines.

Remediation

Users are advised to update to the latest Platform Initialization (PI) firmware version available for their specific processor series. For AMD EPYC processors, the updated PI firmware versions can be obtained through the Original Equipment Manufacturers (OEM). Ryzen Embedded processors also have specific update instructions available through OEMs.

Added: Sep 6, 2025, 5:36 PM
Updated: Sep 6, 2025, 5:36 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
0.6
exploitability
2.4
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.