Bug 2489142

Summary: CVE-2025-61971 linux-firmware: Microcode: Loss of SEV-SNP guest integrity via NBIO register modification [fedora-all]
Product: [Fedora] Fedora Reporter: Vipul Nair <vinair>
Component: linux-firmwareAssignee: David Woodhouse <dwmw2>
Status: CLOSED NOTABUG QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: dvlasenk, dwmw2, evgsyr, jforbes, jwboyer, kernel-maint, pbrobinson
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["e5ffe302-45e2-4e76-94d5-2534acb897cf"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-06-16 14:29:05 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2476925    

Description Vipul Nair 2026-06-16 12:11:22 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Eugene Syromyatnikov 2026-06-16 12:46:49 UTC
The issue[1] pertains AMD SEV blobs (I guess?), that are maintained as part of linux-firmware package, reassigning.

[1] https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3030.html

Comment 2 Peter Robinson 2026-06-16 14:29:05 UTC
This is not covered by the CPU firmware in the linux-firmware package. To quote the linked AMD doc:

"AMD is providing mitigations in Platform Initialization (PI) packages.  Please refer to your OEM for the BIOS update specific to your product."

So HW vendors need to ship BIOS firmware updates to fix these issues.