Database/Firmware, BMC & network fabric
AMD PSP chipset driver - permissive device DACL: The PSP chipset driver's discretionary access control list lets
Impact
The PSP chipset driver's discretionary access control list lets low-privileged users open a handle to the PSP device. Once open, an unprivileged process can query the driver and read back information it should not have - and, more importantly, it has a handle on the secure processor interface that every other PSP bug then becomes reachable through. Weak device permissions are what turn 'requires privilege' into 'requires a shell'.
Who can reach it
Local, unprivileged - which is the notable part. Worth explicitly checking on any node where you hand semi-trusted workloads local execution.
What to do
Fixed by updating the AMD PSP chipset driver package and reloading it or rebooting. Driver-speed rather than BIOS-speed, so this is one you can actually close quickly. Audit the permissions on your PSP/ccp device node as part of the same pass - a device that unprivileged users can open is a standing invitation.
References
Related entries
- AMD SEV-SNP migration agent (report ID assignment): An imported SEV-SNP guest is not assigned a fresh report ID, so theCVE-2021-26349 · AMD SEV-SNP migration agent (report ID assignment)Medium
- AMD Secure Processor TEE - memory cleanup between trusted applications: The ASP's trusted execution environment failsCVE-2021-26393 · AMD Secure Processor TEE - memory cleanup between trusted applicationsMedium
- Arm Trusted Firmware-M: Non-secure world can halt the system, overwrite secure data, or leak secure data via the NSPECVE-2021-27562 · Arm Trusted Firmware-MMedium
- Intel SGX Linux kernel driver: Uncontrolled resource consumption in the in-kernel SGX driver lets a local authenticatedCVE-2021-33135 · Intel SGX Linux kernel driverMedium
- Linux kernel RDMA core (UVERBS_METHOD_QUERY_GID_TABLE): The GID-table query handler used a user-supplied entry sizeCVE-2021-47080 · Linux kernel RDMA core (UVERBS_METHOD_QUERY_GID_TABLE)Medium
- Linux KVM SEV API - host kernel crash from unprivileged guest creation: A non-root host user-level application canCVE-2022-0171 · Linux KVM SEV API - host kernel crash from unprivileged guest creationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.