Database/Control plane, storage & DevOps
AMD System Management Unit (SMU) mailbox interface: A malicious user can manipulate SMU mailbox entries and reach
Impact
A malicious user can manipulate SMU mailbox entries and reach arbitrary code execution in the System Management Unit. The SMU is the microcontroller that owns voltage, clock and thermal control for the package. Code execution there is not just another privilege boundary - it is PHYSICAL control of the part: undervolting to induce computational faults (the technique behind fault-injection attacks on secure enclaves), forcing thermal or power states that throttle or hard-shut-down a node, and doing it in a way the OS reports as a normal thermal event. On a dense GPU rack that is a denial-of-service lever against neighbours and potentially a hardware-damage lever. Sibling issues CVE-2021-26329 and CVE-2021-26330 are the overflow variants in the same interface.
Who can reach it
Local attacker able to reach the SMU mailbox - typically ring 0 on the host, or a bare-metal tenant.
What to do
AGESA / BIOS update per AMD-SB-1021 from the OEM, flash plus reboot. Independently, restrict tenant access to power and thermal management interfaces (no raw MSR access, no vendor overclocking or power-tuning drivers in tenant images) - that mitigation is under your control and does not wait on a BIOS drop. Add out-of-band power and thermal telemetry so an SMU-driven event is distinguishable from a genuine cooling fault.
References
Related entries
- Linux iSCSI: iSCSI netlink structures lack length checksCVE-2021-27365 · Linux iSCSIHigh
- IBM Spectrum Scale core component (format string handling): A user with a shell on any node that runs Storage ScaleCVE-2021-29740 · IBM Spectrum Scale core component (format string handling)High
- Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191: Use-after-freeCVE-2022-29919 · Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191High
- Ceph: ceph-crash.service local privilege escalation to root plus privileged crash-dump disclosureCVE-2022-3650 · CephHigh
- Ampere Altra before 1.08g and Altra Max before 2.05a - return address prediction: An attacker can controlCVE-2022-37459 · Ampere Altra before 1.08g and Altra Max before 2.05a - return address predictionHigh
- IBM Storage Scale Container Native Storage Access (pod security context): A local user in a CNSA-served containerCVE-2022-43831 · IBM Storage Scale Container Native Storage Access (pod security context)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.