GPU VulnDB

Database/Control plane, storage & DevOps

AMD CPU core logic - core hang triggered from an unprivileged VM: MULTI-TENANT ISOLATION: Specific code executed

CVE-2021-26339Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: Specific code executed from an unprivileged VM can hang an AMD CPU core outright. A guest wedges a physical core on the host, denying it to every other workload scheduled there - and on a GPU node whose CPU cores feed data to accelerators, losing cores starves the GPUs. Availability attack from a tenant against the host, requiring no privilege.

Who can reach it

From inside an unprivileged guest VM. No escalation needed - the guest simply executes a particular sequence.

What to do

Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.