A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity.
A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity.
| Vendor | Product | Versions |
|---|---|---|
| AMD | AMD EPYC™ 9004 Series Processors | GenoaPI 1.0.0.G |
| AMD | AMD EPYC™ 7003 Series Processors | MilanPI 1.0.0.H |
| AMD | AMD EPYC™ 9005 Series Processors | TurinPI 1.0.0.5 |
| AMD | AMD EPYC™ 8004 Series Processors | GenoaPI 1.0.0.G |
| AMD | AMD EPYC™ Embedded 7003 Series Processors | EmbMilanPI-SP3 v9 1.0.0.C |
| AMD | AMD EPYC™ Embedded 9003 Series Processors | EmbGenoaPI-SP5 1.0.0.B |
| AMD | AMD EPYC™ Embedded 9005 Series Processors | EmbTurinPI-SP5_1.0.0.1 |
| AMD | AMD EPYC™ Embedded 9004 Series Processors | EmbGenoaPI-SP5 1.0.0.B |
| AMD | AMD EPYC™ Embedded 8004 Series Processors | EmbGenoaPI-SP5 1.0.0.B |
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.