Bug 2489142 - CVE-2025-61971 linux-firmware: Microcode: Loss of SEV-SNP guest integrity via NBIO register modification [fedora-all]
Summary: CVE-2025-61971 linux-firmware: Microcode: Loss of SEV-SNP guest integrity via...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: linux-firmware
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: David Woodhouse
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["e5ffe302-45e2-4e76-94d5-2...
Depends On:
Blocks: CVE-2025-61971
TreeView+ depends on / blocked
 
Reported: 2026-06-16 12:11 UTC by Vipul Nair
Modified: 2026-06-16 14:29 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-06-16 14:29:05 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Vipul Nair 2026-06-16 12:11:22 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Eugene Syromyatnikov 2026-06-16 12:46:49 UTC
The issue[1] pertains AMD SEV blobs (I guess?), that are maintained as part of linux-firmware package, reassigning.

[1] https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3030.html

Comment 2 Peter Robinson 2026-06-16 14:29:05 UTC
This is not covered by the CPU firmware in the linux-firmware package. To quote the linked AMD doc:

"AMD is providing mitigations in Platform Initialization (PI) packages.  Please refer to your OEM for the BIOS update specific to your product."

So HW vendors need to ship BIOS firmware updates to fix these issues.


Note You need to log in before you can comment on or make changes to this bug.