Database/Control plane, storage & DevOps
AMD PSP1 Configuration Block (APCB) parsing: An out-of-bounds memory write while the platform processes the AMD PSP1
Impact
An out-of-bounds memory write while the platform processes the AMD PSP1 Configuration Block. Reaching it requires the ability to modify and re-sign the BIOS image, which is a high bar - but the payoff is memory corruption inside the secure processor's configuration path, i.e. control of the root of trust with a signature that validates.
Who can reach it
Local, and requires both BIOS image modification and the ability to sign the result. That combination points at a signing-key compromise or an insider in the firmware build pipeline rather than a runtime attacker.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string. The signing prerequisite means your firmware supply chain is the real control here - who can sign a BIOS for your fleet, and how is that key held?
References
Related entries
- Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpoint: Code injectionCVE-2023-25549 · Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpointHigh
- Lenovo ThinkSystem SMM / SMM2 and FPC (command injection): An authenticated user with elevated privileges executesCVE-2024-2659 · Lenovo ThinkSystem SMM / SMM2 and FPC (command injection)High
- Schneider Electric Data Center Expert - upgrade bundle signature verification: Improper cryptographic signatureCVE-2024-8531 · Schneider Electric Data Center Expert - upgrade bundle signature verificationHigh
- HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policyCVE-2024-9180 · HashiCorp VaultHigh
- Palo Alto PAN-OS: Admin with mgmt-interface access performs firewall actions as rootCVE-2024-9474 · Palo Alto PAN-OSHigh
- Volcano (scheduler, Elastic service and extender plugin response handling): The scheduler reads unbounded responsesCVE-2025-32777 · Volcano (scheduler, Elastic service and extender plugin response handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.