CVE-2025-0033
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-0033, dubbed "RMPocalypse", is an improper access control vulnerability (CWE-284) in AMD EPYC processors implementing Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP). It involves a race condition in the AMD Secure Processor (ASP) during Reverse Map Table (RMP) initialization that could allow a malicious or compromised hypervisor to modify RMP entries before they are locked, potentially compromising the integrity of SEV-SNP guest memory. Affected processors include AMD EPYC 7003 (Milan), 8004/9004 (Genoa/Bergamo/Siena), and 9005 (Turin) series; earlier generations (Naples, Rome) and certain embedded variants are not affected. Disclosed by AMD on October 13, 2025, it carries a CVSS v3.1 base score of 6.0 (Medium) (AMD Advisory, MSRC).

Technical details

The root cause is improper access control (CWE-284) arising from a race condition in the AMD Secure Processor (ASP) during RMP initialization. When SNP is being initialized, the ASP sets up the Reverse Map Table — a hardware structure that tracks ownership of memory pages for confidential VMs. A malicious hypervisor with administrative privileges can exploit the timing window before RMP entries are locked to inject crafted writes, corrupting the initial RMP content and potentially manipulating which memory pages are attributed to SEV-SNP guests. Exploitation requires local access with high privileges (hypervisor-level control) and does not expose plaintext data or cryptographic secrets — the impact is limited to integrity of guest memory mappings. The vulnerability was reported by researchers Benedict Schlueter, Supraja Sridhara, and Shweta Shinde from ETH Zurich, who published a detailed academic paper on the attack (AMD Advisory, RMPocalypse Paper).

Impact

Successful exploitation allows a malicious or compromised hypervisor to corrupt SEV-SNP guest memory integrity by manipulating RMP entries during initialization. This undermines the core security guarantee of AMD's confidential computing technology — that guest VM memory is protected from a potentially untrusted hypervisor. While the vulnerability does not directly expose plaintext data or cryptographic secrets (confidentiality impact is none), it can enable unauthorized modification of guest memory pages, potentially allowing an attacker to tamper with confidential workloads running in cloud environments such as Azure Confidential Computing (DCasv5/v6, ECasv5/v6, NCC40ads H100 v5 series VMs) (AMD Advisory, MSRC).

Exploitation steps

  1. Gain hypervisor control: The attacker must first obtain administrative/privileged access to the hypervisor layer on a system running AMD EPYC Milan, Genoa, Bergamo, Siena, or Turin processors with SEV-SNP enabled — this is the primary prerequisite.
  2. Target SNP initialization window: Monitor or trigger the SNP initialization sequence on the host, during which the AMD Secure Processor (ASP) sets up the Reverse Map Table (RMP).
  3. Exploit the race condition: During the brief window before RMP entries are locked by the ASP, issue crafted writes to RMP memory from the hypervisor to manipulate page ownership or attribute entries.
  4. Corrupt guest memory integrity: The modified RMP entries cause the SEV-SNP hardware to incorrectly track memory page ownership, allowing the attacker to potentially read or modify memory pages that should be exclusively owned by a confidential guest VM.
  5. Achieve objective: Use the corrupted memory mappings to tamper with confidential workloads, inject malicious data into guest memory, or undermine attestation-based trust assumptions of the SEV-SNP guest (AMD Advisory, RMPocalypse Paper).

Mitigation and workarounds

AMD has released firmware mitigations requiring updates to SEV Firmware and/or Platform Initialization (PI) firmware, distributed via OEM BIOS updates. Key patched versions include: Milan — SEV FW hex 1.37.23 / µcode 0x0A0011DE, or AGESA MilanPI 1.0.0.H; Genoa/Bergamo/Siena — SEV FW 1.37.31 / respective µcodes, or AGESA GenoaPI 1.0.0.H (planned Dec 2025); Turin — SEV FW 1.37.41 / µcode 0x0B002150, or AGESA TurinPI 1.0.0.6. Embedded variants have separate patch timelines (EmbMilanPI-SP3 v9 1.0.0.C and EmbTurinPI-SP5_1.0.0.1 by Oct 31, 2025; EmbGenoaPI-SP5 1.0.0.D by Feb 2026). Organizations should contact their OEM for the applicable BIOS update. Microsoft has noted that Azure Confidential Computing environments have additional security guardrails (isolation, integrity verification, audited management pathways) that reduce risk while patches are applied (AMD Advisory, MSRC).

Community reactions

The vulnerability attracted significant media attention under the "RMPocalypse" moniker coined by the ETH Zurich researchers who discovered it. Coverage appeared across major security outlets including The Hacker News, BleepingComputer, The Register, SecurityOnline, and BankInfoSecurity, with many highlighting the threat to confidential computing in cloud environments. Microsoft published a detailed advisory acknowledging the issue and describing Azure's existing mitigations, emphasizing that no plaintext data is exposed and that host compromise is required. The research was accepted for presentation at CCS 2025, lending academic credibility to the findings. Community discussion on Reddit and Mastodon/Infosec.exchange noted the nuanced severity — serious for confidential computing trust models but constrained by the high privilege prerequisite (The Hacker News, MSRC, RMPocalypse Paper).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64530NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 26, 2026
CVE-2024-14040NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 26, 2026
CVE-2026-64529NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 25, 2026
CVE-2026-64528NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 25, 2026
CVE-2026-64527NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesJul 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management