Database/Firmware, BMC & network fabric
AMD SEV-ES firmware - TMR placement in MMIO space: SEV-ES firmware does not verify that the Trusted Memory Region is
Impact
SEV-ES firmware does not verify that the Trusted Memory Region is outside MMIO space. Point the TMR at MMIO and the secure firmware's private working memory is suddenly backed by device registers the host controls - a route to observing or influencing what the SEV firmware does, costing integrity or availability of confidential guests.
Who can reach it
Hypervisor-privileged attacker who controls where the TMR is placed.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string. This sits inside the SEV-SNP trust boundary, so the update moves the platform's reported TCB version: refresh VCEK certificates from AMD's KDS and update any attestation policy your tenants pin, or confidential guest launches will start failing right after the BIOS lands.
References
Related entries
- AMD Secure Processor firmware - BIOS mailbox command bounds checking: Insufficient bounds checking while the ASPCVE-2021-26402 · AMD Secure Processor firmware - BIOS mailbox command bounds checkingHigh
- Arista EOS (service ACLs): Service ACL bypass for OpenConfig gNOI and RESTCONFCVE-2021-28507 · Arista EOS (service ACLs)High
- Dell Enterprise SONiC OS (information disclosure): An authenticated user can extract sensitive informationCVE-2021-36309 · Dell Enterprise SONiC OS (information disclosure)High
- Linux kernel (drivers/infiniband/sw/siw): A tenant gets an out-of-bounds kernel array read using values it controls.CVE-2022-50736 · Linux kernel (drivers/infiniband/sw/siw)High
- AMD Secure Processor - hardware config integrity across power save/restore: Hardware configuration state is notCVE-2023-31316 · AMD Secure Processor - hardware config integrity across power save/restoreHigh
- AMI MegaRAC SPx (BMC TLS certificate / cryptographic keys): A hard-coded certificate and its private key ship insideCVE-2023-34338 · AMI MegaRAC SPx (BMC TLS certificate / cryptographic keys)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.