GPU VulnDB

Database/Firmware, BMC & network fabric

AMD EPYC / Ryzen - Platform Security Processor privilege escalation: MULTI-TENANT ISOLATION: A direct privilege

CVE-2018-8936Firmware, BMC & network fabricCHIMERA-adjacent PSP escalationcurated

Impact

MULTI-TENANT ISOLATION: A direct privilege escalation into the Platform Security Processor on EPYC server parts. The PSP holds the platform's root of trust, fTPM state and SEV key material, so an attacker who escalates into it owns the security posture of the whole node beneath the hypervisor. Nothing the OS or the hypervisor can do detects or contains it.

Who can reach it

Local, administrator privilege.

What to do

Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.