Description
Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure Processor (ASP), potentially resulting in loss of integrity.
Published: 2026-06-09
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control for the IOMMU register interface could allow a privileged attacker to trigger non-coherent accesses by the AMD Secure Processor, potentially resulting in loss of integrity. The flaw is a missing authorization check that permits manipulation of registers beyond intended bounds. This failure is classified as CWE-1262, reflecting an access‑control weakness. The consequence is limited to data integrity loss; no known path to code execution.

Affected Systems

AMD EPYC 8004 and 9004 series processors, AMD EPYC 9005 series processors, and their embedded equivalents (8004, 9004, 9005). All affected silicon and firmware that implement the IOMMU register interface are vulnerable unless patched.

Risk and Exploitability

The CVSS score of 4 indicates low severity. The EPSS score is < 1%, indicating a low probability of exploitation. The lack of a KEV designation suggests no publicly known exploits. Based on the description, it is inferred that the attacker would need privileged access to modify IOMMU registers, implying a local privilege escalation scenario. Once a privileged attacker triggers non-coherent accesses, the integrity of data processed by the AMD Secure Processor may be compromised.

Generated by OpenCVE AI on August 3, 2026 at 07:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the AMD supplied firmware or BIOS update that addresses the IOMMU register access control flaw (see AMD SB-3039).
  • Restrict or disable direct IOMMU register access for non-privileged contexts to limit the attack surface.
  • Continuously monitor system logs for coherence errors or integrity anomalies to detect potential exploitation.

Generated by OpenCVE AI on August 3, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in IOMMU Register Interface

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Improper access control for register interface in the input-output memory management unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD secure processor (ASP) potentially resulting in loss of integrity. Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure Processor (ASP), potentially resulting in loss of integrity.

Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd epyc 8004 Series Processors
Amd epyc 9004 Series Processors
Amd epyc 9005 Series Processors
Amd epyc Embedded 8004 Series Processors
Amd epyc Embedded 9005 Series Processors
Amd ryzen Embedded V1000 Series Processors
Vendors & Products Amd
Amd epyc 8004 Series Processors
Amd epyc 9004 Series Processors
Amd epyc 9005 Series Processors
Amd epyc Embedded 8004 Series Processors
Amd epyc Embedded 9005 Series Processors
Amd ryzen Embedded V1000 Series Processors

Tue, 09 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Access Control in IOMMU Register Interface

Tue, 09 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper access control for register interface in the input-output memory management unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD secure processor (ASP) potentially resulting in loss of integrity.
Weaknesses CWE-1262
References
Metrics cvssV4_0

{'score': 4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

Amd Epyc 8004 Series Processors Epyc 9004 Series Processors Epyc 9005 Series Processors Epyc Embedded 8004 Series Processors Epyc Embedded 9005 Series Processors Ryzen Embedded V1000 Series Processors
cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-07-23T19:20:37.716Z

Reserved: 2025-07-23T15:01:50.734Z

Link: CVE-2025-54509

cve-icon Vulnrichment

Updated: 2026-06-09T18:56:57.809Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T18:16:32.580

Modified: 2026-06-09T19:30:24.713

Link: CVE-2025-54509

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T07:30:04Z

Weaknesses
  • CWE-1262

    Improper Access Control for Register Interface