Database/Control plane, storage & DevOps
AMD EPYC Server - protected memory region access control: Insufficient access control over protected memory regions on
Impact
Insufficient access control over protected memory regions on EPYC server parts lets privileged code read and write memory that the platform reserves for security purposes - including regions used by SMM and the secure processor. An attacker uses it to get persistence and to reach data the hardware was supposed to fence off from the OS entirely.
Who can reach it
Local, requires administrator privilege on the host. EPYC server silicon specifically, which is what makes this batch relevant to a datacenter rather than a desktop.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string.
References
Related entries
- PC-DDR4 / LPDDR4X DRAM - Target Row Refresh mitigation: Non-uniform Rowhammer patterns triggered bit flips on every oneCVE-2021-42114 · PC-DDR4 / LPDDR4X DRAM - Target Row Refresh mitigationCritical
- Digi RealPort protocol (Digi console/terminal servers): RealPort is the protocol Digi console servers use to exposeCVE-2023-4299 · Digi RealPort protocol (Digi console/terminal servers)Critical
- Ivanti Connect Secure: Stack-based buffer overflowCVE-2025-0282 · Ivanti Connect SecureCritical
- Ivanti Connect Secure/ZTA: Stack-based buffer overflowCVE-2025-22457 · Ivanti Connect Secure/ZTACritical
- GitLab: unsanitized HTML in the CI job modal lets a developer-role user escalate privilegesCVE-2026-16627 · GitLab CE/EE (CI job modal HTML rendering)Critical
- Woodpecker CI: pipeline authors can pick any ServiceAccount for their build podsCVE-2026-61549 · Woodpecker CI Kubernetes backend (backend_options.kubernetes.serviceAccountName)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.