AMD EPYC 7003
cpe:2.3:h:amd:epyc_7001:*:*:*:*:*:*:*, +5 more
A vulnerability exists in certain AMD CPUs that may allow an admin-privileged attacker to alter the CPU pipeline configuration, potentially corrupting the stack pointer in an SEV-SNP guest. This issue arises from improper access controls that enable a malicious hypervisor to manipulate internal configuration bits, particularly affecting guests on the same SMT thread.
Exploitation of this vulnerability could lead to unauthorized modification of the stack pointer in an SEV-SNP guest, causing stack corruption.
Users are advised to update to the recommended Platform Initialization (PI) firmware version. Specific guidance can be found in the AMD Security Bulletin AMD-SB-3027.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.