CVE-2025-29950 - CVE House
Back to Database
Status published High CVE-2025-29950

Improper input validation in system management mode (SMM) could allow...

Vulnerability Description

Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory leading to arbitrary code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-29950

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Reported through AMD Bug Bounty Program

Affected Vendor

Affected Software

AMD EPYC™ 9004 Series Processors, AMD EPYC™ 7003 Series Processors, AMD EPYC™ 7002 Series Processors, AMD EPYC™ 7001 Series Processors, AMD EPYC™ 9005 Series Processors, AMD Instinct™ MI300A, AMD EPYC™ 9V64H Processor, AMD Ryzen™ Threadripper™ PRO 3000WX Processors, AMD Ryzen™ Threadripper™ PRO 5000 WX-Series Processors, AMD Ryzen™ Threadripper™ 7000 Processors, AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors, AMD Ryzen™ Threadripper™ 9000 Processors, AMD Ryzen™ Threadripper™ PRO 9000 WX-Series Processors, AMD EPYC™ Embedded 7003 Series Processors, AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Genoa"), AMD EPYC™ Embedded 7002 Series Processors, AMD EPYC™ Embedded 3000 Series Processors, AMD EPYC™ Embedded 9005 Series Processors, AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Bergamo"), AMD EPYC™ Embedded 8004 Series Processors
Vulnerable Versions:
GenoaPI 1.0.0.G, MilanPI 1.0.0.H, RomePI 1.0.0.N, NaplesPI 1.0.0.R, TurinPI 1.0.0.6, MI300A 1.0.0.B, MI300C 1.0.0.2, ChagallWSPI-sWRX8 1.0.0.C, CastlePeakWSPI-sWRX8 1.0.0.I, StormPeakPI-SP6_1.0.0.1l, ShimadaPeakPI-SP6_1.0.0.1, StormPeakPI-SP6_1.1.0.0j, EmbMilanPI-SP3 v9 1.0.0.C, EmbGenoaPI-SP5 1.0.0.B, EmbRomePI-SP3 1.0.0.F, SnowyOwl_SP4_SP4r2.1.1.0.H, EmbTurinPI-SP5_1.0.0.1

Timeline

Official Publish: February 10th, 2026
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.