Database/Control plane, storage & DevOps
AGESA Boot Loader (ABL) - SPI ROM header input validation (AMD-SB-3003): The AGESA Boot Loader does not properly
Impact
The AGESA Boot Loader does not properly validate SPI ROM headers, so malformed header content is acted on during early boot. Anything that runs before signature enforcement is fully established is disproportionately valuable to an attacker regardless of its CVSS.
Who can reach it
Local, requires SPI ROM write access - root plus flash, a compromised BMC, or supply-chain access.
What to do
Fixed in AMD PI/AGESA firmware and delivered only as an OEM SBIOS package - AMD ships the PI drop to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before releasing BIOS. **Budget one to six months of OEM lag**, and note that several CVEs in this batch are marked 'no fix planned' on Naples (EPYC 7001) - for those the only remediation is retiring the hardware. Applying it means cordon, drain and a full power cycle per node; there is no driver reload, no live patch and no VBIOS step. Enable platform SPI write protection as the compensating control; boot-time parsers cannot be defended from the OS.
References
Related entries
- Redis: Lua environment weakness lets a user inject code that runs with another Redis user's privilegesCVE-2022-24735 · RedisLow
- Slurm (X11 forwarding, xauth magic-cookie setup): Slurm shells out to xauth to install a user's X11 magic cookie, andCVE-2020-27746 · Slurm (X11 forwarding, xauth magic-cookie setup)Low
- Zabbix: Some setup.php steps reachable by unauthenticated usersCVE-2022-23134 · ZabbixLow
- SkyPilot (sky/users/server.py, user ID derivation from username): User IDs are derived with a weak hash of theCVE-2026-13482 · SkyPilot (sky/users/server.py, user ID derivation from username)Low
- GitLab: unauthenticated GraphQL requests can read CI/CD job traces containing secret variable valuesCVE-2026-4523 · GitLab CE/EE (GraphQL API, CI/CD job traces)Low
- NATS server (TLS ciphersuite selection via CLI flags): A configuration footgun in the cluster message bus: NATSNCVD-2021-017-nats-server-tls-ciphersuite-sele · NATS server (TLS ciphersuite selection via CLI flags)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.