Database/Firmware, BMC & network fabric
AMD SMM module: heap overflow yields SMM code execution when chained with an SPI flash write flaw
Impact
A heap overflow in an SMM module lets an attacker who already holds a separate primitive for writing SPI flash execute code in System Management Mode, the most privileged execution context on the board - below the hypervisor, below the host OS, and invisible to anything a tenant-facing security stack can observe. On a compromised node that means firmware-level persistence that survives reimaging and redeployment, so the usual wipe-and-return-to-fleet response does not clear it. AMD lists 2nd through 4th Gen EPYC and Instinct MI300A explicitly, so GPU compute nodes are in scope alongside general-purpose servers. AMD rates it 7.4 local with high attack complexity: the chained SPI-write precondition is doing real work, and this is not exploitable on its own.
Who can reach it
Local attacker on the host who already has access to a second vulnerability permitting writes to SPI flash. AMD scores it PR:N with high attack complexity; there is no remote or network path.
What to do
Apply the AGESA-based BIOS update your server OEM ships for AMD-SB-7009 - AMD publishes the fixed AGESA version per processor generation, but the flashable image comes from the platform vendor, and the fixed AGESA differs across 2nd/3rd/4th Gen EPYC and MI300A. Cost is a firmware flash with the node out of service and a full power cycle; MI300A nodes have to be drained of GPU workloads first, which is the expensive part on a busy fleet. Check the bulletin for your exact model before scheduling, since not every SKU shares a release date.
References
Related entries
- shim (verify_sbat_section): Integer overflow leading to heap overflow while verifying the SBAT section on 32-bitCVE-2023-40548 · shim (verify_sbat_section)High
- Intel SGX (L1 terminal fault on enclave pages): Speculative execution lets code outside an enclave read the enclave'sCVE-2018-3615 · Intel SGX (L1 terminal fault on enclave pages)High
- AMD Secure Processor Secure OS - memory buffer checking: A malicious trusted application can read and write the ASPCVE-2022-23817 · AMD Secure Processor Secure OS - memory buffer checkingHigh
- Lenovo XClarity Controller (XCC) - LDAP/AD authorization: When XCC is configured to authenticate against ActiveCVE-2023-29057 · Lenovo XClarity Controller (XCC) - LDAP/AD authorizationHigh
- BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmwareCVE-2023-29164 · BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmware…High
- Linux bnxt_en driver (bnxt_fill_hw_rss_tbl): Memory out-of-bounds in the RSS indirection-table path of the Broadcom NICCVE-2024-44933 · Linux bnxt_en driver (bnxt_fill_hw_rss_tbl)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.