Back to search
CVE-2025-48517
Published: Feb 10, 2026
Modified: Feb 10, 2026
PUBLISHED
Description
Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guest with an ASID in the range meant for SEV-SNP guests potentially resulting in a partial loss of confidentiality.
| Vendor | Product | Versions |
|---|---|---|
AMD | AMD EPYC™ 9005 Series Processors | unaffected TurinPI 1.0.0.6 |
AMD | AMD EPYC™ Embedded 9005 Series Processors | unaffected EmbTurinPI-SP5_1.0.0.1 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now