Database/Firmware, BMC & network fabric
AMD PSP trusted applications shipped in the AMD Graphics Driver: Trusted applications bundled with the AMD graphics
Impact
Trusted applications bundled with the AMD graphics driver and running on the PSP do not validate their parameters, letting a local attacker bypass security restrictions and get arbitrary code execution in the secure processor. Notable because the entry point is the GPU driver stack rather than platform firmware - a GPU-adjacent compromise reaching the platform root of trust.
Who can reach it
Local, via the graphics driver's PSP interface.
What to do
Fixed by updating the AMD graphics driver package (which carries the PSP trusted applications), then reloading the driver or rebooting the node. Unlike the pure-firmware ASP issues this does not wait on an OEM BIOS cycle - it moves at driver-release speed, so it is one of the cheaper ASP-class fixes to deploy.
References
Related entries
- AMD Secure Processor (ASP) drivers: Improper parameter handling in the ASP driver layer lets an already-privilegedCVE-2020-12930 · AMD Secure Processor (ASP) driversHigh
- AMD Secure Processor (ASP) kernel: Improper parameter handling in the ASP's own kernel gives a privileged attackerCVE-2020-12931 · AMD Secure Processor (ASP) kernelHigh
- AMD PSP - System Management Network privileged register zeroing: An attacker can zero any privileged register on theCVE-2020-12961 · AMD PSP - System Management Network privileged register zeroingHigh
- ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed): The driver brings the video engineCVE-2020-36787 · ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed)High
- Intel RDMA driver for Ethernet X722 and 800 series (Linux): Improper input validation in the Intel RDMA Linux driverCVE-2021-0084 · Intel RDMA driver for Ethernet X722 and 800 series (Linux)High
- BMC firmware on the HPE Cloudline whitebox line: An attacker directs the BMC's video-deletion routine at arbitraryCVE-2021-25124 · BMC firmware on the HPE Cloudline whitebox lineHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.