Database/Firmware, BMC & network fabric
AMD Secure Processor - TEE parameter handling: A privileged attacker can hand an arbitrary memory value to functions
Impact
A privileged attacker can hand an arbitrary memory value to functions inside the trusted execution environment, reaching arbitrary code execution in the ASP. At CVSS 8.7 this is one of the more direct host-root-to-secure-processor escalations in the set: the OS administrator, who is supposed to be outside the ASP trust boundary, gets inside it.
Who can reach it
Local, privileged (host root). No physical access and no signed-TA requirement.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Because this sits inside the SEV-SNP trust boundary, the update also moves the platform's reported TCB version: after patching you must refresh VCEK certificates from AMD's KDS and update whatever attestation policy your tenants (or your own confidential-VM control plane) pin against, or every guest launch will start failing validation.
References
Related entries
- UEFI firmware SMM modules in Intel reference platform firmware (SMM handler, FlashUcAcmSmm, ImcErrorHandler, WheaERSTCVE-2025-20105 · UEFI firmware SMM modules in Intel reference platform firmwareHigh
- Arista CVX: authenticated Redis session escalates to root on every server in the CVX clusterCVE-2025-5088 · Arista CloudVision eXchange (CVX) Redis serviceHigh
- AMI AptioV UEFI firmware: incomplete input validation lets a privileged local user execute code in firmware contextCVE-2026-33197 · AMI AptioV UEFI firmware (BIOS input validation)High
- Linux kernel mlx5_core eswitch / vport (SR-IOV): Mlx5_core sizes a firmware command buffer from the physical function'sCVE-2026-53230 · Linux kernel mlx5_core eswitch / vport (SR-IOV)High
- Arista EOS gNMI: crafted request from an authenticated client executes code as rootCVE-2026-73464 · Arista EOS (gNMI - gRPC Network Management Interface)High
- Cisco FXOS / NX-OS AAA: AAA implementation flaw enabling remote DoS via brute-force login attempts against the switchCVE-2017-3883 · Cisco FXOS / NX-OS AAAHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.