Executive brief
A vulnerability in how AMD-based systems process memory module metadata could allow an attacker with high-level system access or physical access to corrupt data within virtual machines. This issue affects the integrity of guest memory, potentially allowing an attacker to bypass isolation boundaries between the host and virtualized environments. While difficult to exploit, it poses a risk to the reliability and security of data in cloud or multi-tenant computing environments.
Technical details
This vulnerability stems from improper input validation of Serial Presence Detect (SPD) metadata, which contains configuration information for DIMM memory modules. An attacker with physical access, Ring 0 (kernel-level) privileges on a system with non-compliant hardware, or control over the BIOS Root of Trust can exploit this flaw to overwrite memory assigned to guest virtual machines. The attack requires high privileges or physical proximity and targets the integrity of the guest memory space. AMD has identified this as CWE-20 (Improper Input Validation) and issued an advisory (AMD-SB-3015) regarding the impact on guest data integrity.
Affected products
- AMD BIOS / UEFI Firmware
Timeline
- 2026-06-10: disclosed: Initial publication of the CVE and AMD security bulletin.