Database/Firmware, BMC & network fabric
AMD Secure Processor (ASP) firmware system-call interface: The ASP firmware does not validate addresses passed across
Impact
The ASP firmware does not validate addresses passed across its system-call boundary, so a compromised user application that can issue ASP syscalls can steer the secure processor into reading or writing memory of the caller's choosing, ending in code execution inside the ASP. That converts a userspace compromise into control of the platform's security engine.
Who can reach it
Local. Requires an already-compromised application with ASP syscall access - typically a privileged agent or a trusted application, not a plain tenant container.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string.
References
Related entries
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP memory-region allocation stores the memory object into the MR andCVE-2021-47012 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/rxe): When soft-RoCE queue-pair initialisation fails, the QP structure is left fullCVE-2021-47078 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel (drivers/infiniband/core): The core set the send and receive completion-queue pointers on a queue pairCVE-2021-47196 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/rep): The neighbour-update worker takes a reference on anCVE-2021-47247 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/rep)High
- Linux kernel (drivers/infiniband/core): The RDMA connection-manager state machine can be driven in a circle so twoCVE-2021-47391 · Linux kernel (drivers/infiniband/core)High
- Linux kernel InfiniBand qib driver (user SDMA path, qib_user_sdma_pkt): The user SDMA descriptor path did arithmetic onCVE-2021-47485 · Linux kernel InfiniBand qib driver (user SDMA path, qib_user_sdma_pkt)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.