CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.
AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.
Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.
Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service.
A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.
Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2022-10-25
N/A
7.5 HIGH
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
