Description
Improper restriction of operations in the IOMMU could allow a malicious hypervisor to access guest private memory resulting in loss of integrity.
Published: 2025-09-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-35662 Improper restriction of operations in the IOMMU could allow a malicious hypervisor to access guest private memory resulting in loss of integrity.
History

Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd epyc
Amd epyc 7003
Amd epyc 8004
Amd epyc 9004
Vendors & Products Amd
Amd epyc
Amd epyc 7003
Amd epyc 8004
Amd epyc 9004

Mon, 08 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 06 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Description Improper restriction of operations in the IOMMU could allow a malicious hypervisor to access guest private memory resulting in loss of integrity.
Weaknesses CWE-119
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2025-09-08T20:03:47.167Z

Reserved: 2023-04-27T15:25:41.427Z

Link: CVE-2023-31351

cve-icon Vulnrichment

Updated: 2025-09-08T20:03:43.774Z

cve-icon NVD

Status : Deferred

Published: 2025-09-06T17:15:31.867

Modified: 2026-04-15T00:35:42.020

Link: CVE-2023-31351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-09T21:32:01Z

Weaknesses