Database/Firmware, BMC & network fabric
AMD Secure Processor kernel - DRAM mapping into protected areas (AMD-SB-3003): An access-control gap in the ASP kernel
Impact
An access-control gap in the ASP kernel allows DRAM to be mapped into areas the secure processor treats as protected. Mapping attacker-influenced DRAM into a protected region is how you get the secure processor to operate on data it believes is trustworthy - low score, but it is a building block rather than an endpoint.
Who can reach it
Local, privileged, through the ASP interface.
What to do
Fixed in AMD PI/AGESA firmware and delivered only as an OEM SBIOS package - AMD ships the PI drop to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before releasing BIOS. **Budget one to six months of OEM lag**, and note that several CVEs in this batch are marked 'no fix planned' on Naples (EPYC 7001) - for those the only remediation is retiring the hardware. Applying it means cordon, drain and a full power cycle per node; there is no driver reload, no live patch and no VBIOS step. Marked 'no fix planned' on Naples (EPYC 7001) - on that generation the remediation is hardware retirement, which for 2017-era EPYC in an AI fleet is likely already overdue on performance grounds.
References
Related entries
- Intel SGX SDK (Edger8r code generator): The Edger8r tool generates the trusted/untrusted bridge code for enclavesCVE-2025-32004 · Intel SGX SDK (Edger8r code generator)Low
- Intel SGX DCAP for Windows: Input-validation flaw in the Windows DCAP components allowing local information disclosureCVE-2023-42776 · Intel SGX DCAP for WindowsLow
- AMD processors - speculative inference of control registers despite UMIP: Part of the Transient Scheduler Attacks batchCVE-2024-36348 · AMD processors - speculative inference of control registers despite UMIPLow
- AMD processors - speculative inference of TSC_AUX when reads are disabled: Sibling of the other Transient SchedulerCVE-2024-36349 · AMD processors - speculative inference of TSC_AUX when reads are disabledLow
- Hitachi VSP One Block: firmware update path does not validate the image before applying itCVE-2025-0824 · Hitachi Virtual Storage Platform One Block 23/24/26/28 (firmware update validation)Low
- Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledCVE-2026-0995 · Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.