Vulnerability Intelligence Report
CVE-2025-29936
Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation resulting in loss of confidentiality.
No Active Exploit Signals
CVSS Base Score
8.4
HIGH
EPSS Probability:0.10%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-20 ↗CWE-20 Improper Input Validation
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| AMD | AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt R") | 7.06.02.123 (unaffected) |
| AMD | AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Phoenix") | 7.06.02.123 (unaffected) |
| AMD | AMD Ryzen™ AI 300 Series Processors (formerly codenamed "Strix Point") | 7.06.02.123 (unaffected) |
| AMD | AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics (formerly codenamed "Hawk Point") | 7.06.02.123 (unaffected) |
| AMD | AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics (formerly codenamed "Rembrandt") | 7.06.02.123 (unaffected) |
| AMD | AMD Ryzen™ Al Max+ | 7.06.02.123 (unaffected) |
| AMD | AMD Ryzen™ Embedded 8000 Series Processors | amd_chipset_software_7.06.02.123.exe (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.104%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Advanced Micro Devices Inc. · Vendor · USA |
| Reserved | 2025-03-12T15:14:59 |
| Published | 2026-05-15T01:52:13 |
| Patch Date | 2026-05-15 |
| Last Updated | 2026-05-15T13:28:48 |
Community Chatter & Buzz