Database/Control plane, storage & DevOps
AMD SMM - memory corruption (AMD-SB-4003): Memory corruption reachable in System Management Mode. Same class as the
Impact
Memory corruption reachable in System Management Mode. Same class as the rest of the SMM cluster - a ring-0 attacker escalates into the one execution context that no hypervisor, kernel or EDR can observe, and the foothold survives OS reinstallation.
Who can reach it
Local, ring-0 privilege required.
What to do
Fixed in AMD PI/AGESA firmware and delivered only as an OEM SBIOS package - AMD ships the PI drop to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before releasing BIOS. **Budget one to six months of OEM lag**, and note that several CVEs in this batch are marked 'no fix planned' on Naples (EPYC 7001) - for those the only remediation is retiring the hardware. Applying it means cordon, drain and a full power cycle per node; there is no driver reload, no live patch and no VBIOS step.
References
Related entries
- AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory access: Improper privilegeCVE-2023-20598 · AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory accessHigh
- HPE OneView (command injection with local privilege escalation): A low-privileged local user on the OneView applianceCVE-2023-50274 · HPE OneView (command injection with local privilege escalation)High
- OpenVPN: Stack overflow in the interactive serviceCVE-2024-27459 · OpenVPNHigh
- Intel QuickAssist Technology (QAT) software and driversCVE-2024-31858 · Intel QuickAssist Technology (QAT) software and drivers - QAT software before 2.2.0, with a 2025 batch through 2.6.0High
- IBM Storage Scale GUI (local privilege escalation): A local privilege escalation in the Storage Scale GUI availableCVE-2024-31891 · IBM Storage Scale GUI (local privilege escalation)High
- Linux HID/amd_sfh - driver_data freed after HID device destruction: A use-after-free in the AMD Sensor Fusion Hub HIDCVE-2024-46746 · Linux HID/amd_sfh - driver_data freed after HID device destructionHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.