Database/Firmware, BMC & network fabric
AMD SEV-SNP - VM_HSAVE_PA MSR validation: Insufficient validation of the VM_HSAVE_PA model-specific register lets a
Impact
Insufficient validation of the VM_HSAVE_PA model-specific register lets a malicious hypervisor point the host-state save area somewhere it should not be, breaking SEV-SNP guest memory integrity. The RMP is supposed to make it impossible for the host to write guest pages; this is a way around that using an MSR the host legitimately controls.
Who can reach it
Requires host/hypervisor privilege - the SEV-SNP adversary model exactly. No guest cooperation needed.
What to do
Fixed in AMD SEV firmware / AGESA and reaches you as an OEM SBIOS package - AMD hands AGESA to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before shipping BIOS. **Budget one to six months of OEM lag**, longer on older platforms and sometimes never on end-of-support SKUs. Applying it means draining the host and doing a full power cycle. Because the fix moves the platform's reported SEV-SNP TCB version, you must also pull fresh VCEK certificates from AMD's Key Distribution Service and update any attestation policy your tenants pin - otherwise guests will start failing launch validation the moment the BIOS lands. Some SEV firmware can alternatively be staged from linux-firmware (amd/amd_sev_*.sbin) and committed via the ccp driver at boot, which is faster than waiting on BIOS - check whether your platform supports firmware hot-load before assuming the OEM is the only route.
References
Related entries
- OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end): bmcweb is the single process behind Redfish, the webCVE-2022-2809 · OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end)High
- AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackCVE-2022-2827 · AMI MegaRACHigh
- Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU): UsbCoreDxe builds its USB transaction working bufferCVE-2022-30283 · Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU)High
- OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix): The second bug the fuzzer foundCVE-2022-3409 · OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix)High
- Dell Enterprise SONiC OS (SSH cryptographic key): A cryptographic key weakness in SONiC's SSH implementation letsCVE-2022-34425 · Dell Enterprise SONiC OS (SSH cryptographic key)High
- Intel OpenBMC firmware (before version 0.72) - network-facing service: An unauthenticated caller reads out of boundsCVE-2022-35729 · Intel OpenBMC firmware (before version 0.72) - network-facing serviceHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.