GPU VulnDB

Database/Firmware, BMC & network fabric

AMD processors - power reporting side channel against SEV VMs: MULTI-TENANT ISOLATION: An authenticated attacker uses

CVE-2023-20575Firmware, BMC & network fabriccurated

Impact

MULTI-TENANT ISOLATION: An authenticated attacker uses the platform's power reporting functionality to monitor execution inside an AMD SEV VM. The whole promise of SEV is that the host cannot see what the confidential guest is doing; power telemetry is a channel the memory encryption does not cover, so a host operator watches the guest's execution profile through the power meter. For anyone selling confidential computing on EPYC this is a direct hole in the product claim.

Who can reach it

Local, authenticated, with access to power reporting interfaces on a host running SEV guests.

What to do

Mitigated by restricting access to power reporting interfaces and by AGESA-level changes to reduce telemetry resolution. Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch. The immediately actionable step is to lock down who can read host power telemetry on confidential-computing nodes - that is a permissions change, not a maintenance window.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.