Database/Control plane, storage & DevOps
AMD CPU core logic - core hang triggered from an unprivileged VM: Specific code executed from an unprivileged VM can
Impact
Specific code executed from an unprivileged VM can hang an AMD CPU core outright. A guest wedges a physical core on the host, denying it to every other workload scheduled there - and on a GPU node whose CPU cores feed data to accelerators, losing cores starves the GPUs. Availability attack from a tenant against the host, requiring no privilege.
Who can reach it
From inside an unprivileged guest VM. No escalation needed - the guest simply executes a particular sequence.
What to do
Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch.
References
Related entries
- AMD AGESA Boot Loader (ABL) / ASP stage-2 bootloader: A malicious or compromised User Application or AGESA Boot LoaderCVE-2021-26361 · AMD AGESA Boot Loader (ABL) / ASP stage-2 bootloaderMedium
- Intel 82599 Ethernet Controllers and Adapters - network-on-chip shared-resource isolation: Improper isolation of sharedCVE-2021-33096 · Intel 82599 Ethernet Controllers and Adapters - network-on-chip shared-resource isolationMedium
- Imagination PowerVR GPU driver - cache subsystem information page: The driver's cache-subsystem information pageCVE-2022-20235 · Imagination PowerVR GPU driver - cache subsystem information pageMedium
- Linux swiotlb - info leak with DMA_FROM_DEVICE bounce buffers: The software IO TLB leaks information through bounceCVE-2022-48853 · Linux swiotlb - info leak with DMA_FROM_DEVICE bounce buffersMedium
- Broadcom LSI Storage Authority (LSA) - on-disk credential/key storage on Linux and Windows: The keys LSA usesCVE-2023-4327 · Broadcom LSI Storage Authority (LSA) - on-disk credential/key storage on Linux and WindowsMedium
- Linux x86/mm - pfn_to_kaddr() 64-bit input handling (SNP support code): On 64-bit platforms the pfn_to_kaddr() macroCVE-2023-52659 · Linux x86/mm - pfn_to_kaddr() 64-bit input handling (SNP support code)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.