Flipping one bit leaves AMD CPUs open to VM vuln
ID: 8b3caf67-2603-5da4-918c-b506216bdac2
STIX ID: report--8b3caf67-2603-5da4-918c-b506216bdac2
Feed Name: The Register (Security)
Threat Score
StackWarp (CVE-2025-29943) is a microarchitectural flaw in AMD Zen CPUs that abuses an undocumented MSR bit to freeze and manipulate the frontend stack engine, enabling a hypervisor-controlled or SMT sibling thread to deterministically alter a SEV‑SNP guest's stack pointer. The researchers demonstrated RSA-2048 private key recovery, OpenSSH and sudo password bypasses, and ring-0 code execution; proof-of-concept code and paper are published and AMD has released patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
