Mechanism · TEE remote attestation for AI workloads
Software-only forgery of SEV-SNP attestation (RMPocalypse, Fabricked)
On this page
Evidence scope
Critical on affected SEV-SNP platforms before the vendor fixes. These attacks need privileged host software, not physical access. Mitigated records AMD's released updates; it does not establish that a particular deployment installed or enforces them 6 7 34 35.
Researchers at ETH Zurich showed that a malicious hypervisor can corrupt the Reverse Map Table (RMP) while SEV-SNP initialises it. SEV-SNP uses the RMP to store security metadata for every DRAM page, and a single 8-byte overwrite leaves the whole table compromised. The attack needs no physical access. The authors confirmed it on Zen 3, Zen 4 and Zen 5 processors and state that it affects all AMD processors that support SEV-SNP. They demonstrated forged attestation values, debugging enabled on production confidential VMs, reads and writes of encrypted VM memory, and replay of VM register state 6.
AMD assigned CVE-2025-0033 6. Its bulletin rates the issue medium severity and reports SEV firmware, microcode or platform firmware updates for every affected EPYC server and embedded series, with release dates from June 2025 to February 2026 7.
In Fabricked, researchers from the same ETH Zurich group showed that a host controlling the hypervisor and UEFI firmware can misconfigure the Infinity Fabric interconnect so that the AMD Secure Processor initialises SEV-SNP incorrectly. On a Zen 5 EPYC processor this gave arbitrary reads and writes in the victim VM and forged attestation reports 34. AMD assigned CVE-2025-54510, rates it medium severity and reports platform firmware updates for its EPYC 7003, 8004, 9004 and 9005 server series, released in November and December 2025 35.