Database/Firmware, BMC & network fabric
AMD SEV / SEV-ES - guest address space rearrangement undetected by attestation: A malicious hypervisor can rearrange
Impact
A malicious hypervisor can rearrange memory in the guest's address space and the SEV attestation mechanism does not notice, because attestation measures content rather than placement. That lets the host reorder the guest's own encrypted pages to build a different program out of the same measured bytes - the attestation report still validates while the VM executes something the tenant never wrote. This is the failure that makes 'the attestation passed' an insufficient answer on SEV/SEV-ES.
Who can reach it
Malicious hypervisor. Affects SEV and SEV-ES; SEV-SNP addresses it with the reverse-map table enforcing page ownership and mapping.
What to do
**Not fixable on SEV or SEV-ES** - migrate confidential workloads to SEV-SNP, where the RMP enforces the guest-physical to system-physical mapping. Practically that means EPYC Milan (7003) or newer with SNP enabled in SBIOS and a VMM that launches SNP guests. If you are attesting SEV/SEV-ES guests today, understand that a passing attestation report does not establish the guest is running the code that was measured.
References
Related entries
- Intel TXT SINIT Authenticated Code Module for some Intel processors: Improper initialization in the SINIT ACMCVE-2022-30704 · Intel TXT SINIT Authenticated Code Module for some Intel processorsHigh
- Intel Xeon memory controller configuration (with SGX): Memory controller configuration registers are left withCVE-2022-33196 · Intel Xeon memory controller configuration (with SGX)High
- Intel Xeon processors (SGX/TDX error injection): Unauthorised error injection against SGX or TDX on affected Xeon partsCVE-2022-41804 · Intel Xeon processors (SGX/TDX error injection)High
- NVIDIA DGX BMC (AMI-derived management controller): The BMC's SPX REST API lets an authorised attacker read and writeCVE-2022-42278 · NVIDIA DGX BMC (AMI-derived management controller)High
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's SPX REST API accepts injected shell commandsCVE-2023-25507 · NVIDIA DGX BMC (AMI-derived management controller)High
- AMD Power Management Firmware (PMFW) - unintended proxy to the System Management Unit: The GPU power managementCVE-2023-31313 · AMD Power Management Firmware (PMFW) - unintended proxy to the System Management UnitHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.