Database/Firmware, BMC & network fabric
AMD SEV-SNP - debug exception delivery to guests: A privileged attacker can suppress delivery of debug exceptions
Impact
A privileged attacker can suppress delivery of debug exceptions to SEV-SNP guests. The guest does not get debug information it expects, which is mostly an availability and observability problem - but for a guest that relies on debug exceptions as part of a self-protection or integrity-checking scheme, silently swallowing them removes that check.
Who can reach it
Privileged host attacker against a confidential guest.
What to do
Fixed in AMD SEV firmware / AGESA and reaches you as an OEM SBIOS package - AMD hands AGESA to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before shipping BIOS. **Budget one to six months of OEM lag**, longer on older platforms and sometimes never on end-of-support SKUs. Applying it means draining the host and doing a full power cycle. Because the fix moves the platform's reported SEV-SNP TCB version, you must also pull fresh VCEK certificates from AMD's Key Distribution Service and update any attestation policy your tenants pin - otherwise guests will start failing launch validation the moment the BIOS lands. Some SEV firmware can alternatively be staged from linux-firmware (amd/amd_sev_*.sbin) and committed via the ccp driver at boot, which is faster than waiting on BIOS - check whether your platform supports firmware hot-load before assuming the OEM is the only route. Low priority relative to the RMP-bypass and microcode issues; batch it into the next BIOS wave.
References
Related entries
- AMD CPU microcode - RDRAND entropy after patch load: Incomplete cleanup after loading a microcode patch degrades theCVE-2024-21977 · AMD CPU microcode - RDRAND entropy after patch loadLow
- AMD CPU cache initialization - SEV-SNP guest memory integrity: Improper initialization of CPU cache memory lets aCVE-2024-36331 · AMD CPU cache initialization - SEV-SNP guest memory integrityLow
- AMD IOMMU access control - SEV-SNP RMP check bypass (AMD-SB-3009): An IOMMU access-control flaw lets a privilegedCVE-2023-20581 · AMD IOMMU access control - SEV-SNP RMP check bypass (AMD-SB-3009)Low
- Intel TDX module firmware: Missing check for an exceptional condition in the TDX module allows a privileged userCVE-2024-27457 · Intel TDX module firmwareLow
- AMI MegaRAC SPx (embedded lighttpd web server): Use-after-free in the lighttpd request parser embedded in MegaRAC SPxCVE-2018-25103 · AMI MegaRAC SPx (embedded lighttpd web server)Low
- Intel TDX firmware: Improper synchronisation in TDX firmware, exploitable by a privileged host user to escalateCVE-2025-22853 · Intel TDX firmwareLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.