
Proof-of-concept for CVE-2025-29943 exploiting an undocumented stack engine bit in AMD Zen CPUs to corrupt the stack pointer in SEV-SNP protected VMs, enabling arbitrary code execution and privilege escalation.
Proof of concept for the StackWarp hardware vulnerability (CVE-2025-29943) in AMD processors. This flaw allows an attacker with administrator privileges on a host (hypervisor) to manipulate the CPU pipeline configuration to corrupt the stack pointer within a SEV-SNP guest virtual machine, leading to privilege escalation and arbitrary code execution.
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:NThe vulnerability lies in a microarchitectural optimization (the stack engine) and can be triggered by an undocumented control bit. A malicious hypervisor can exploit it to alter the control flow and data within a confidential virtual machine (CVM), bypassing SEV-SNP integrity guarantees without needing to decrypt its memory.