Database/Firmware, BMC & network fabric
Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms): A backdoor in the Promontory chipset firmware. The
Impact
A backdoor in the Promontory chipset firmware. The chipset sits on the DMA path for USB, SATA and PCIe, so code running there can read and write host memory independently of the CPU and outside the reach of anything the OS enforces. Included as the canonical example of the risk class rather than as an EPYC issue: third-party chipset silicon in your server has its own firmware, its own DMA capability, and usually no attestation story at all.
Who can reach it
Local, requires the ability to load chipset firmware. Ryzen/Ryzen Pro client platforms rather than EPYC servers.
What to do
Fixed by a chipset firmware update from the OEM, delivered in a BIOS package - drain plus power cycle. Verify applicability before spending a window: this is client-platform silicon and almost certainly not in your EPYC server fleet. The transferable lesson for a datacenter operator is to ask which non-AMD firmware images your server actually loads at boot and who signs them.
References
Related entries
- AMD EPYC / Ryzen - Platform Security Processor privilege escalation: A direct privilege escalation into the PlatformCVE-2018-8936 · AMD EPYC / Ryzen - Platform Security Processor privilege escalationCritical
- APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmware: A heap overflow inCVE-2022-22805 · APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmwareCritical
- APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machine: A TLS authentication bypass byCVE-2022-22806 · APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machineCritical
- Dell Enterprise SONiC (authentication): A critical step in authentication is missing, so an unauthenticated remoteCVE-2024-45764 · Dell Enterprise SONiC (authentication)Critical
- Arista EOS OSPFv3: crafted packet restarts the routing agentCVE-2026-73455 · Arista EOS (OSPFv3 routing agent)High
- Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c): The canonical RDMA isolationCVE-2014-8159 · Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.