GPU VulnDB

Database/Control plane, storage & DevOps

AMD AGESA Boot Loader (ABL) / ASP stage-2 bootloader: MULTI-TENANT ISOLATION: A malicious or compromised User

CVE-2021-26361Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: A malicious or compromised User Application or AGESA Boot Loader can exfiltrate arbitrary memory from the ASP stage-2 bootloader. What leaks is firmware memory at the deepest pre-boot stage - the material an attacker needs to build a reliable secure-processor exploit, and potentially key state handled during early boot.

Who can reach it

Local, requires control of a UApp or the ABL itself, so firmware-level access rather than OS-level.

What to do

Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.