Database/Firmware, BMC & network fabric
BIOS Authenticated Code Module (ACM) for a broad set of Intel processors, including Xeon Scalable: Improper access
Impact
Improper access control (plus, in the sibling CVEs, an out-of-bounds write and an input-validation flaw) in the BIOS ACM. ACMs are Intel-signed code that runs in the authenticated-code execution mode used to establish the root of trust for Boot Guard and TXT - it is more privileged than SMM and more privileged than the hypervisor. Code execution or state corruption at ACM level lets an attacker subvert the measurement chain from underneath, which means a platform can present a valid measured-boot report while running attacker-controlled firmware. Persistence at this level is below-the-OS, survives reimage, and defeats attestation-based tenant-handoff checks.
Who can reach it
A privileged local user - local root or SMM-capable code on the host. On bare-metal GPU nodes handed to tenants with root, that is the tenant.
What to do
The ACM ships inside the BIOS image, so the fix is a BIOS/platform-firmware update from the OEM (Dell, HPE, Supermicro, Lenovo, Gigabyte, Quanta, Wiwynn) - reboot and job drain, and for a May 2022 Intel advisory the OEM server BIOS releases spread across the rest of 2022. There is no configuration workaround: you cannot disable the ACM. If your fleet's trust story depends on Boot Guard or TXT measurements, treat un-updated nodes as not attestable.
References
Related entries
- ASPEED LPC control driver (drivers/soc/aspeed/aspeed-lpc-ctrl.c) in the OpenBMC kernel: A process on the BMC that canCVE-2021-42252 · ASPEED LPC control driver (drivers/soc/aspeed/aspeed-lpc-ctrl.c) in the OpenBMC kernelHigh
- AMD Secure Processor (ASP) firmware system-call interface: The ASP firmware does not validate addresses passed acrossCVE-2021-46771 · AMD Secure Processor (ASP) firmware system-call interfaceHigh
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP memory-region allocation stores the memory object into the MR andCVE-2021-47012 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/rxe): When soft-RoCE queue-pair initialisation fails, the QP structure is left fullCVE-2021-47078 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel (drivers/infiniband/core): The core set the send and receive completion-queue pointers on a queue pairCVE-2021-47196 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/rep): The neighbour-update worker takes a reference on anCVE-2021-47247 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/rep)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.