CVE-2025-29943
published 2026-01-16CVE-2025-29943: Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the…
PriorityP420medium4.6CVSS 4.0
AVLACLATNPRHUINVCNVINVANSCNSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.20%
10.2th percentile
Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | amd64-microcode | < amd64-microcode 3.20251202.1 (forky) | amd64-microcode 3.20251202.1 (forky) |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv4.04.6MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv4.6MEDIUM
vendor_msrc9.8CRITICAL
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
AMD EPYC™ 9004 Series Processors: From CVEorg collector
vendor_redhat·2026-01-16·CVSS 4.6
CVE-2025-29943 [MEDIUM] CWE-123 AMD EPYC™ 9004 Series Processors: From CVEorg collector
AMD EPYC™ 9004 Series Processors: From CVEorg collector
Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.
Debian
CVE-2025-29943: amd64-microcode - Write what were condition within AMD CPUs may allow an admin-privileged attacker...
vendor_debian·2025·CVSS 4.6
CVE-2025-29943 [MEDIUM] CVE-2025-29943: amd64-microcode - Write what were condition within AMD CPUs may allow an admin-privileged attacker...
Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.20251202.1)
sid: resolved (fixed in 3.20251202.1)
trixie: open
Microsoft
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.
vendor_msrc·2024-03-12·CVSS 9.8
CVE-2024-29943 [CRITICAL] CWE-125 An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Marin
GHSA
GHSA-4vw8-pffj-q9x7: Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting
ghsa_unreviewed·2026-01-16
CVE-2025-29943 [MEDIUM] CWE-123 GHSA-4vw8-pffj-q9x7: Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting
Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.
OSV
CVE-2025-29943: Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting
osv·2026-01-16·CVSS 4.6
CVE-2025-29943 [MEDIUM] CVE-2025-29943: Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting
Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-29943 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.6
CVE-2025-29943 [MEDIUM] CVE-2025-29943 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-29943 :
Linux Debian vulnerability analysis and mitigation
Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.
Source : NVD
## 4.6
Score
Published January 16, 2026
Severity MEDIUM
CNA Score 4.6
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
amd64-microcode
Sources
NVD
Debian 11 No Fix Added at: Jan 20, 2026
Echo No Fix Added at: Jan 20, 2026
Ubuntu 16.04, 18.04, 20.04, 22.04, 24.04, 25.
Bugzilla
CVE-2025-29943 AMD EPYC™ 9004 Series Processors: From CVEorg collector
bugzilla·2026-01-16·CVSS 4.6
CVE-2025-29943 [MEDIUM] CVE-2025-29943 AMD EPYC™ 9004 Series Processors: From CVEorg collector
CVE-2025-29943 AMD EPYC™ 9004 Series Processors: From CVEorg collector
Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.
2026-01-16
Published