Database/Firmware, BMC & network fabric
AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002): A use-after-free in
Impact
A use-after-free in the SNP guest context page lets a malicious hypervisor masquerade as the guest's migration agent. The guest then negotiates its migration with the attacker instead of a legitimate MA - which is to say it hands over the state that memory encryption existed to protect, voluntarily, to the party it was protecting itself from.
Who can reach it
Malicious or compromised hypervisor. Only exercised where SEV-SNP live migration is enabled.
What to do
Fixed in AMD PI/AGESA firmware and delivered only as an OEM SBIOS package - AMD ships the PI drop to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before releasing BIOS. **Budget one to six months of OEM lag**, and note that several CVEs in this batch are marked 'no fix planned' on Naples (EPYC 7001) - for those the only remediation is retiring the hardware. Applying it means cordon, drain and a full power cycle per node; there is no driver reload, no live patch and no VBIOS step. Because this touches the SEV-SNP trust boundary, the update moves the platform TCB version: refresh VCEK certificates from AMD's KDS and update tenant attestation policy, or confidential guest launches will fail immediately after the BIOS lands. If you do not offer live migration for confidential VMs, the path is unreachable and this can wait for the next firmware wave. If you do, disable it until the fleet is patched - that is a scheduler policy change, not a maintenance window.
References
Related entries
- Intel TDX firmware (PRNG seeding): A predictable seed in the TDX firmware's pseudo-random number generator. PredictableCVE-2025-20613 · Intel TDX firmware (PRNG seeding)Low
- AMD SEV-SNP - debug exception delivery to guests: A privileged attacker can suppress delivery of debug exceptionsCVE-2023-20573 · AMD SEV-SNP - debug exception delivery to guestsLow
- AMD CPU microcode - RDRAND entropy after patch load: Incomplete cleanup after loading a microcode patch degrades theCVE-2024-21977 · AMD CPU microcode - RDRAND entropy after patch loadLow
- AMD CPU cache initialization - SEV-SNP guest memory integrity: Improper initialization of CPU cache memory lets aCVE-2024-36331 · AMD CPU cache initialization - SEV-SNP guest memory integrityLow
- AMD IOMMU access control - SEV-SNP RMP check bypass (AMD-SB-3009): An IOMMU access-control flaw lets a privilegedCVE-2023-20581 · AMD IOMMU access control - SEV-SNP RMP check bypass (AMD-SB-3009)Low
- Intel TDX module firmware: Missing check for an exceptional condition in the TDX module allows a privileged userCVE-2024-27457 · Intel TDX module firmwareLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.