CVE-2025-48517
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-48517 is an access control vulnerability in AMD Secure Encrypted Virtualization (SEV) firmware affecting AMD EPYC 9005 Series Processors ("Turin"/"Turin Dense") and AMD EPYC Embedded 9005 Series Processors. The flaw involves insufficient granularity of access control that allows a privileged user with a malicious hypervisor to create a SEV-ES guest with an Address Space ID (ASID) in the range reserved for SEV-SNP guests, potentially resulting in a partial loss of confidentiality. It was discovered internally by AMD and initially published on February 10, 2026. The vulnerability carries a CVSS v4.0 base score of 4.6 (Medium) (AMD Advisory).

Technical details

The root cause is classified as CWE-1220 (Insufficient Granularity of Access Control). The SEV firmware fails to enforce strict separation between ASID ranges allocated to SEV-ES guests and those reserved for SEV-SNP guests. A privileged attacker controlling a malicious hypervisor can exploit this by assigning a SEV-SNP-range ASID to a SEV-ES guest, potentially allowing that guest to access or infer memory regions intended to be isolated under SEV-SNP protections. The attack vector is local, requires high privileges (hypervisor-level control), and no user interaction is needed. No public proof-of-concept code has been identified (AMD Advisory).

Impact

Successful exploitation results in a partial loss of confidentiality within virtualized environments using AMD SEV-SNP. A malicious hypervisor operator could potentially read or infer memory contents belonging to SEV-SNP-protected guest VMs, undermining the confidential computing guarantees that SEV-SNP is designed to provide. Integrity and availability are not impacted by this specific vulnerability. The scope is limited to cloud or multi-tenant environments where SEV-SNP is deployed and the hypervisor is under adversarial control (AMD Advisory).

Exploitability

No public exploit code or in-the-wild exploitation has been reported for CVE-2025-48517. The vulnerability was discovered internally by AMD and disclosed through coordinated vulnerability disclosure. The EPSS score is approximately 0.012%, indicating a very low probability of near-term exploitation. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high-privilege access (hypervisor control), significantly limiting the attacker population (AMD Advisory).

Mitigation and workarounds

AMD has released firmware fixes for affected processors. For AMD EPYC 9005 Series ("Turin"/"Turin Dense") processors, the fix is included in TurinPI 1.0.0.6 (released 2025-06-30) with SEV FW 1.37.41 (SPL[SEV]=0x4). For AMD EPYC Embedded 9005 Series processors, the fix is included in EmbTurinPI-SP5 1.0.0.1 (released 2025-10-31). AMD recommends contacting your OEM for the specific BIOS update applicable to your product. No configuration-based workaround is listed for this CVE (AMD Advisory).

Community reactions

HPE published a security advisory (HPESBHF04999) referencing the AMD-SB-3023 bulletin, indicating OEM partners are actively tracking and distributing mitigations. Community coverage has been limited given the medium severity and the requirement for privileged hypervisor access. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (HPE Advisory, AMD Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

amd64-microcode

Affected

sid

amd64-microcode

Affected

trixie

amd64-microcode

Affected

Ubuntu

Affected

bionic (esm-infra)

amd64-microcode

Not Affected

devel

amd64-microcode

Affected

focal (esm-infra)

amd64-microcode

Not Affected

jammy

amd64-microcode

Not Affected

noble

amd64-microcode

Affected

resolute

amd64-microcode

Affected

trusty (esm-infra-legacy)

amd64-microcode

Not Affected

xenial (esm-infra-legacy)

amd64-microcode

Not Affected

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-90776HIGH8.7
  • Grafana logoGrafana
  • grafana.src
NoNoSep 13, 2026
CVE-2026-90783HIGH8.5
  • Linux Debian logoLinux Debian
  • mkvtoolnix
NoNoSep 13, 2026
CVE-2026-90775HIGH7.1
  • Linux Debian logoLinux Debian
  • address-standardizer
NoNoSep 13, 2026
CVE-2026-90781MEDIUM4.8
  • Linux Debian logoLinux Debian
  • alsa-lib
NoNoSep 13, 2026
CVE-2026-90773LOW2.4
  • Linux Debian logoLinux Debian
  • rust-procs
NoNoSep 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management