Database/Firmware, BMC & network fabric
AMD Secure Processor (ASP) kernel: Improper parameter handling in the ASP's own kernel gives a privileged attacker
Impact
Improper parameter handling in the ASP's own kernel gives a privileged attacker a path to elevate inside the secure processor and damage platform integrity. Same practical outcome as the ASP driver flaw: root on the box becomes control of the firmware trust anchor.
Who can reach it
Local, privileged.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string.
References
Related entries
- AMD PSP - System Management Network privileged register zeroing: An attacker can zero any privileged register on theCVE-2020-12961 · AMD PSP - System Management Network privileged register zeroingHigh
- ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed): The driver brings the video engineCVE-2020-36787 · ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed)High
- Intel RDMA driver for Ethernet X722 and 800 series (Linux): Improper input validation in the Intel RDMA Linux driverCVE-2021-0084 · Intel RDMA driver for Ethernet X722 and 800 series (Linux)High
- BMC firmware on the HPE Cloudline whitebox line: An attacker directs the BMC's video-deletion routine at arbitraryCVE-2021-25124 · BMC firmware on the HPE Cloudline whitebox lineHigh
- AMD PSP boot ROM - integrity of decrypted firmware image: The PSP boot ROM authenticates and decrypts firmware but doesCVE-2021-26315 · AMD PSP boot ROM - integrity of decrypted firmware imageHigh
- AMD SEV-ES Trusted Memory Region - SNP guest memory integrity: A bug in the SEV-ES Trusted Memory Region handling costsCVE-2021-26324 · AMD SEV-ES Trusted Memory Region - SNP guest memory integrityHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.