Database/Firmware, BMC & network fabric
AMD SEV-ES Trusted Memory Region - SNP guest memory integrity: A bug in the SEV-ES Trusted Memory Region handling costs
Impact
A bug in the SEV-ES Trusted Memory Region handling costs memory integrity for SNP-active VMs. The TMR is the region the SEV firmware itself works in; a defect there means the component enforcing confidential-VM isolation can have its own working memory disturbed, and SNP guests lose the integrity guarantee they were sold.
Who can reach it
Requires host/hypervisor privilege on a machine running SNP guests.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string. This sits inside the SEV-SNP trust boundary, so the update moves the platform's reported TCB version: refresh VCEK certificates from AMD's KDS and update any attestation policy your tenants pin, or confidential guest launches will start failing right after the BIOS lands.
References
Related entries
- AMD Secure Processor (ASP) bootloader - image header parsing: The ASP bootloader reads and acts on fields from aCVE-2021-26335 · AMD Secure Processor (ASP) bootloader - image header parsingHigh
- AMD Secure Processor - SoC security-configuration registers: A local attacker can make unauthorised changes to theCVE-2021-26360 · AMD Secure Processor - SoC security-configuration registersHigh
- AMD SEV-ES - bounds checking on Reverse Map table memory: Insufficient bounds checking in SEV-ES lets an attackerCVE-2021-26409 · AMD SEV-ES - bounds checking on Reverse Map table memoryHigh
- Arista EOS (AAA API): Incorrect AAA API usage enables unrestricted local device accessCVE-2021-28500 · Arista EOS (AAA API)High
- Arista EOS (TerminAttr AAA): TerminAttr streaming-telemetry agent bypasses AAA, giving unauthorized local device accessCVE-2021-28501 · Arista EOS (TerminAttr AAA)High
- BIOS Authenticated Code Module (ACM) for a broad set of Intel processors, including Xeon Scalable: Improper accessCVE-2021-33123 · BIOS Authenticated Code Module (ACM) for a broad set of Intel processors, including Xeon ScalableHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.