AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this vulnerability leading to leaking guest data by the malicious hypervisor.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1013 | mitigation vendor advisory |
http://www.openwall.com/lists/oss-security/2022/08/08/6 | third party advisory mailing list |