AMD Secure Encrypted Virtualization
cpe:2.3:o:amd:secure_encrypted_virtualization_firmware:*:*:*:*:*:*:*
- >= 1.37.20, < 1.37.23
A use-after-free vulnerability has been identified in the Secure Encrypted Virtualization (SEV) firmware of AMD EPYC processors. This vulnerability could allow a malicious hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent, potentially leading to a loss of integrity. The issue affects several AMD EPYC processor series, including 7001, 7002, 7003, 8004, 9004, and 9005, all within the AMD EPYC Embedded product line.
Exploitation of this vulnerability could result in a loss of integrity for the affected virtual machine.
Users can update to the recommended AMD EPYC Platform Initialization (PI) or SEV firmware versions. Specific update instructions can be obtained from the original equipment manufacturer (OEM).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.