CVE-2025-61972: AMD Epyc 8004 Series Processors

High severity, CVSS 8.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity.

Affected products

  • AMD AMD Epyc 8004 Series Processors
  • AMD AMD Epyc 9004 Series Processors
  • AMD AMD Epyc 9005 Series Processors
  • AMD AMD Epyc Embedded 8004 Series Processors
  • AMD AMD Epyc Embedded 9004 Series Processors Formerly Codenamed Bergamo
  • AMD AMD Epyc Embedded 9004 Series Processors Formerly Codenamed Genoa
  • AMD AMD Epyc Embedded 9005 Series Processors

Published 2026-05-13. Last modified 2026-06-17.