CVE-2025-29936 PUBLISHED

Assigner: AMD
Reserved: 12.03.2025 Published: 15.05.2026 Updated: 15.05.2026

Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation resulting in loss of confidentiality.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 8.4

Product Status

Vendor AMD
Product AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt R")
Versions Default: affected
  • Version 7.06.02.123 is unaffected
Vendor AMD
Product AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Phoenix")
Versions Default: affected
  • Version 7.06.02.123 is unaffected
Vendor AMD
Product AMD Ryzen™ AI 300 Series Processors (formerly codenamed "Strix Point")
Versions Default: affected
  • Version 7.06.02.123 is unaffected
Vendor AMD
Product AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Hawk Point")
Versions Default: affected
  • Version 7.06.02.123 is unaffected
Vendor AMD
Product AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt")
Versions Default: affected
  • Version 7.06.02.123 is unaffected
Vendor AMD
Product AMD Ryzen™ Al Max+
Versions Default: affected
  • Version 7.06.02.123 is unaffected
Vendor AMD
Product AMD Ryzen™ Embedded 8000 Series Processors
Versions Default: affected
  • Version amd_chipset_software_7.06.02.123.exe is unaffected

Credits

  • Reported through AMD Bug Bounty Program

References

Problem Types

  • CWE-20 Improper Input Validation CWE