Database/Firmware, BMC & network fabric
AMD SEV-ES - bounds checking on Reverse Map table memory: Insufficient bounds checking in SEV-ES lets an attacker
Impact
Insufficient bounds checking in SEV-ES lets an attacker corrupt Reverse Map table memory, breaking SEV-SNP memory integrity. The RMP is the single data structure that decides which physical page belongs to which guest; corrupting it is the most direct possible attack on confidential-VM isolation, because after that the hardware itself believes the wrong owner.
Who can reach it
Host/hypervisor-privileged attacker.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string. This sits inside the SEV-SNP trust boundary, so the update moves the platform's reported TCB version: refresh VCEK certificates from AMD's KDS and update any attestation policy your tenants pin, or confidential guest launches will start failing right after the BIOS lands. Treat RMP-corruption issues as the top tier of your SEV patch queue - everything else in SNP rests on the RMP being correct.
References
Related entries
- Arista EOS (AAA API): Incorrect AAA API usage enables unrestricted local device accessCVE-2021-28500 · Arista EOS (AAA API)High
- Arista EOS (TerminAttr AAA): TerminAttr streaming-telemetry agent bypasses AAA, giving unauthorized local device accessCVE-2021-28501 · Arista EOS (TerminAttr AAA)High
- BIOS Authenticated Code Module (ACM) for a broad set of Intel processors, including Xeon Scalable: Improper accessCVE-2021-33123 · BIOS Authenticated Code Module (ACM) for a broad set of Intel processors, including Xeon ScalableHigh
- ASPEED LPC control driver (drivers/soc/aspeed/aspeed-lpc-ctrl.c) in the OpenBMC kernel: A process on the BMC that canCVE-2021-42252 · ASPEED LPC control driver (drivers/soc/aspeed/aspeed-lpc-ctrl.c) in the OpenBMC kernelHigh
- AMD Secure Processor (ASP) firmware system-call interface: The ASP firmware does not validate addresses passed acrossCVE-2021-46771 · AMD Secure Processor (ASP) firmware system-call interfaceHigh
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP memory-region allocation stores the memory object into the MR andCVE-2021-47012 · Linux kernel (drivers/infiniband/sw/siw)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.