Database/Firmware, BMC & network fabric
AMD SEV guest VMs - TLB flush after VMCB creation sequence: The CPU may fail to flush the TLB after a particular
Impact
The CPU may fail to flush the TLB after a particular sequence involving creation of a new VMCB in SEV guest VMs. Stale translations across a VM boundary mean one guest's memory can be reached through another's cached mapping - the low CVSS reflects the difficulty of arranging the sequence, not the severity of what happens if you do.
Who can reach it
Requires a host able to arrange a specific VMCB creation sequence - hypervisor-privileged.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string. This sits inside the SEV-SNP trust boundary, so the update moves the platform's reported TCB version: refresh VCEK certificates from AMD's KDS and update any attestation policy your tenants pin, or confidential guest launches will start failing right after the BIOS lands.
References
Related entries
- AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002): A use-after-free inCVE-2023-20519 · AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002)Low
- Intel TDX firmware (PRNG seeding): A predictable seed in the TDX firmware's pseudo-random number generator. PredictableCVE-2025-20613 · Intel TDX firmware (PRNG seeding)Low
- AMD SEV-SNP - debug exception delivery to guests: A privileged attacker can suppress delivery of debug exceptionsCVE-2023-20573 · AMD SEV-SNP - debug exception delivery to guestsLow
- AMD CPU microcode - RDRAND entropy after patch load: Incomplete cleanup after loading a microcode patch degrades theCVE-2024-21977 · AMD CPU microcode - RDRAND entropy after patch loadLow
- AMD CPU cache initialization - SEV-SNP guest memory integrity: Improper initialization of CPU cache memory lets aCVE-2024-36331 · AMD CPU cache initialization - SEV-SNP guest memory integrityLow
- AMD IOMMU access control - SEV-SNP RMP check bypass (AMD-SB-3009): An IOMMU access-control flaw lets a privilegedCVE-2023-20581 · AMD IOMMU access control - SEV-SNP RMP check bypass (AMD-SB-3009)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.