Executive brief
A security vulnerability in AMD hardware components could allow a local user with administrative privileges to bypass certain memory protections. This issue affects the integrity of Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) guests, which are designed to keep virtual machines isolated and secure even from a compromised host. An attacker could potentially manipulate hardware routing to interfere with the data or operations of these secure virtual environments.
Technical details
The vulnerability is classified as CWE-1233 (Security-Sensitive Hardware Controls with Missing Lock Bit Protection). Specifically, certain Northbridge I/O (NBIO) registers do not implement lock bits to prevent unauthorized modification after system initialization. A local attacker with high privileges (Administrator/Root) can exploit this to modify Memory-Mapped I/O (MMIO) routing configurations. This manipulation can lead to a loss of integrity for AMD SEV-SNP guest virtual machines, as the hardware-level isolation mechanisms rely on stable MMIO configurations. The issue was disclosed by AMD in advisory AMD-SB-3030.
Affected products
- AMD NBIO (Northbridge I/O) Firmware
Timeline
- 2026-05-13: disclosed: Initial disclosure by AMD and NVD publication.