CVE-2025-0033

Publication date 14 October 2025

Last updated 26 June 2026


Ubuntu priority

Cvss 3 Severity Score

6.0 · Medium

Score breakdown

Description

Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.

Read the notes from the security team

Status

Package Ubuntu Release Status
amd64-microcode 26.04 LTS resolute
Vulnerable
25.10 questing
Vulnerable
25.04 plucky Ignored end of life, was needs-triage
24.04 LTS noble
Vulnerable
22.04 LTS jammy
Vulnerable
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable
16.04 LTS xenial
Vulnerable
14.04 LTS trusty Ignored no real-world users

Notes


rodrigo-zaiden

This is not planned to be fixed for the amd64-microcode package in Ubuntu 14.04 as that release was already outside of the LTS timeframe when this hardware platform was launched. AMD SB mentions fix in both SEV (amd/) and ucode (amd-ucode/) binaries. AMD released ucode patches for: Milan: 0x0A0011DE / Milan-X: 0xA001245 Genoa: 0x0A101156 / Genoa-X: 0x0A101251 Bergamo/Siena: 0x0AA0021B Turin Classic: 0x0B002150 / Turin Dense: 0x0B10104D These patches are included in upstream Version: 2025-07-29 (commit 3768c184): Microcode patches in microcode_amd_fam19h.bin: Family=0x19 Model=0x01 Stepping=0x01: Patch=0x0a0011de Length=5568 bytes Family=0x19 Model=0x01 Stepping=0x02: Patch=0x0a001247 Length=5568 bytes Family=0x19 Model=0x11 Stepping=0x01: Patch=0x0a101158 Length=5568 bytes Family=0x19 Model=0x11 Stepping=0x02: Patch=0x0a101253 Length=5568 bytes Family=0x19 Model=0xa0 Stepping=0x02: Patch=0x0aa0021c Length=5568 bytes Microcode patches in microcode_amd_fam1ah.bin: Family=0x1a Model=0x02 Stepping=0x01: Patch=0x0b002151 Length=14368 bytes Family=0x1a Model=0x11 Stepping=0x00: Patch=0x0b10104e Length=14368 bytes AMD advisory mentions SEV release in: Milan (fam 19h model 01h): SEV FW 1.37.23 (1.55.35) Genoa (fam 19h model 11h): SEV FW 1.37.31 (1.55.49) Turin (fam 1a model 02h): SEV FW 1.37.41 (1.55.65) Upstream including these versions is found in commit 13786e87: Update AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors with models in the range 00h to 0fh. Update AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors with models in the range 10h to 1fh. Update AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors with models in the range 00h to 0fh.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
amd64-microcode

Severity score breakdown

CVSS version: CVSS v3.0

Base score 6.0 · Medium

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N


Access our resources on patching vulnerabilities