CVE-2023-20519: AMD Genoapi Firmware

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.

Affected products

  • AMD Genoapi Firmware: before 1.0.0.3 (fixed in 1.0.0.3)
  • AMD Milanpi Firmware: before 1.0.0.a (fixed in 1.0.0.a)

Published 2023-11-14. Last modified 2026-06-17.