Database/Firmware, BMC & network fabric
AMD processors - power reporting side channel against SEV VMs: MULTI-TENANT ISOLATION: An authenticated attacker uses
Impact
MULTI-TENANT ISOLATION: An authenticated attacker uses the platform's power reporting functionality to monitor execution inside an AMD SEV VM. The whole promise of SEV is that the host cannot see what the confidential guest is doing; power telemetry is a channel the memory encryption does not cover, so a host operator watches the guest's execution profile through the power meter. For anyone selling confidential computing on EPYC this is a direct hole in the product claim.
Who can reach it
Local, authenticated, with access to power reporting interfaces on a host running SEV guests.
What to do
Mitigated by restricting access to power reporting interfaces and by AGESA-level changes to reduce telemetry resolution. Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch. The immediately actionable step is to lock down who can read host power telemetry on confidential-computing nodes - that is a permissions change, not a maintenance window.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.