Database/Firmware, BMC & network fabric
AMD PSP - System Management Network privileged register zeroing: An attacker can zero any privileged register on the
Impact
An attacker can zero any privileged register on the System Management Network via the PSP. Zeroing SMN registers is a general-purpose way to disable platform protections - lock bits, access-control gates, security configuration - which turns into a bypass of whatever those registers were enforcing. It is a primitive rather than a single bug: whatever protection you were relying on at the SMN level can be switched off.
Who can reach it
Local, privileged, through the PSP interface.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string.
References
Related entries
- ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed): The driver brings the video engineCVE-2020-36787 · ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed)High
- Intel RDMA driver for Ethernet X722 and 800 series (Linux): Improper input validation in the Intel RDMA Linux driverCVE-2021-0084 · Intel RDMA driver for Ethernet X722 and 800 series (Linux)High
- BMC firmware on the HPE Cloudline whitebox line: An attacker directs the BMC's video-deletion routine at arbitraryCVE-2021-25124 · BMC firmware on the HPE Cloudline whitebox lineHigh
- AMD PSP boot ROM - integrity of decrypted firmware image: The PSP boot ROM authenticates and decrypts firmware but doesCVE-2021-26315 · AMD PSP boot ROM - integrity of decrypted firmware imageHigh
- AMD SEV-ES Trusted Memory Region - SNP guest memory integrity: A bug in the SEV-ES Trusted Memory Region handling costsCVE-2021-26324 · AMD SEV-ES Trusted Memory Region - SNP guest memory integrityHigh
- AMD Secure Processor (ASP) bootloader - image header parsing: The ASP bootloader reads and acts on fields from aCVE-2021-26335 · AMD Secure Processor (ASP) bootloader - image header parsingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.