StackWarp is a newly disclosed hardware vulnerability (CVE-2025-29943) affecting AMD Zen 1–5 processors that allows privileged attackers to execute code inside SEV-SNP protected confidential virtual machines. The flaw exploits an undocumented control bit to manipulate the CPU's stack engine, enabling attackers to corrupt the stack pointer and hijack control flow without reading encrypted VM memory. It affects AMD EPYC 7003, 8004, 9004, and 9005 series processors. AMD released microcode updates in July and October 2025, with additional patches scheduled for April 2026. Operators should consider disabling hyperthreading on critical systems and apply available firmware updates.

3m read timeFrom thehackernews.com
Post cover image
6 Impressions