CVE-2023-20585: AMD Epyc 7003 Series Processors

Medium severity, CVSS 5.6. EPSS: 0.1% chance of exploitation in the next 30 days.

Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity.

Affected products

  • AMD AMD Epyc 7003 Series Processors
  • AMD AMD Epyc 9004 Series Processors
  • AMD AMD Epyc Embedded 7003 Series Processors
  • AMD AMD Epyc Embedded 9004 Series Processors

Published 2026-04-16. Last modified 2026-06-17.