AMD EPYC 7001
cpe:2.3:h:amd:epyc_7001:*:*:*:*:*:*:*, +1 more
A denial-of-service vulnerability has been identified in various AMD processors, including EPYC, Athlon, Ryzen, and Ryzen Embedded series. The issue arises from improper handling of direct memory writes in the input-output memory management unit, allowing a malicious guest virtual machine (VM) to flood the host with writes. This could trigger a fatal machine check error, causing a crash that disrupts all co-located guest VMs.
Exploitation of this vulnerability can lead to a host system crash, triggered by a fatal machine check error caused by an excessive flood of malformed System Management Interrupts (SMIs) from a guest VM. This crash can create a denial-of-service condition for all guest VMs running on the affected host.
AMD has released mitigations for this vulnerability in the Platform Initialization (PI) or Secure Encrypted Virtualization (SEV) firmware versions for EPYC processors. However, for Athlon and Ryzen processors, no fix is planned. Users should contact their Original Equipment Manufacturer (OEM) for the specific BIOS update related to this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.