CVE-2025-54509: AMD Epyc 8004 Series Processors

Medium severity, CVSS 4.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure Processor (ASP), potentially resulting in loss of integrity.

Affected products

  • AMD AMD Epyc 8004 Series Processors
  • AMD AMD Epyc 9004 Series Processors
  • AMD AMD Epyc 9005 Series Processors
  • AMD AMD Epyc Embedded 8004 Series Processors
  • AMD AMD Epyc Embedded 9004 Series Processors Formerly Codenamed Bergamo
  • AMD AMD Epyc Embedded 9004 Series Processors Formerly Codenamed Genoa
  • AMD AMD Epyc Embedded 9005 Series Processors

Published 2026-06-09. Last modified 2026-07-23.