Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-61971

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 6
EPSS Низкий

Описание

Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing configurations, potentially resulting in loss of SEV-SNP guest integrity.

A flaw was found in the microcode that manages NBIO registers. A local attacker with administrative privileges could exploit a missing security control, allowing them to alter critical system configurations. This could compromise the integrity of virtual machines protected by Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP), potentially leading to unauthorized data tampering or execution within the guest.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10microcode_ctlOut of support scope
Red Hat Enterprise Linux 8microcode_ctlFix deferred
Red Hat Enterprise Linux 9microcode_ctlFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2476925microcode_ctl: Microcode: Loss of SEV-SNP guest integrity via NBIO register modification

EPSS

Процентиль: 2%
0.00116
Низкий

6 Medium

CVSS3

Связанные уязвимости

nvd
3 месяца назад

Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing configurations, potentially resulting in loss of SEV-SNP guest integrity.

EPSS

Процентиль: 2%
0.00116
Низкий

6 Medium

CVSS3