Database/Firmware, BMC & network fabric
AMD processors - frequency scaling / power management: A remote or local attacker times operations and infers secret
Impact
A remote or local attacker times operations and infers secret data from how DVFS frequency scaling responds to the data being processed - turning a power side channel into a timing side channel that works over the network. On a GPU host node the exposure is the CPU-side crypto: TLS termination for your API, key material in the control plane, tenant secrets handled by the host. It does not read GPU memory.
Who can reach it
An authenticated attacker able to time operations on the target, including remotely for network-facing crypto. Co-tenancy is not required, which is what made Hertzbleed notable.
What to do
AMD's guidance is not a microcode patch: the fix is constant-time or blinded implementations in the affected cryptographic software, and optionally disabling frequency boost - which costs you real performance on every workload on the node. Practically: update OpenSSL/libcrypto and any SIKE-like primitives, and treat disabling boost as a last resort. Effectively UNPATCHABLE at the silicon level.
References
Related entries
- Intel processors - power management throttling: The Intel half of Hertzbleed: observable behaviour in power-managementCVE-2022-24436 · Intel processors - power management throttlingMedium
- Ampere Altra / Altra Max processors: The Arm-server variant of HertzbleedCVE-2022-35888 · Ampere Altra / Altra Max processorsMedium
- AMI MegaRAC SPx (BMC cryptography / HMAC): A step is missing when the BMC generates its HMAC, so the authentication tagCVE-2023-34471 · AMI MegaRAC SPx (BMC cryptography / HMAC)Medium
- AMD Video Decoder Engine Firmware (VCN FW) - debug code left active: Debug code was shipped active in AMD's Video CoreCVE-2024-36319 · AMD Video Decoder Engine Firmware (VCN FW) - debug code left activeMedium
- EDK II NetworkPkg (IScsiDxe, iSCSI login response processing): A hostile iSCSI target answers the firmware initiatorCVE-2024-38805 · EDK II NetworkPkg (IScsiDxe, iSCSI login response processing)Medium
- Lenovo XClarity Administrator (LXCA, insufficient authorization): An authenticated LXCA user without sufficientCVE-2024-45104 · Lenovo XClarity Administrator (LXCA, insufficient authorization)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.