GPU VulnDB

Database/Firmware, BMC & network fabric

AMD SMM module: heap overflow yields SMM code execution when chained with an SPI flash write flaw

CVE-2023-20577Firmware, BMC & network fabriccurated

Impact

A heap overflow in an SMM module lets an attacker who already holds a separate primitive for writing SPI flash execute code in System Management Mode, the most privileged execution context on the board - below the hypervisor, below the host OS, and invisible to anything a tenant-facing security stack can observe. On a compromised node that means firmware-level persistence that survives reimaging and redeployment, so the usual wipe-and-return-to-fleet response does not clear it. AMD lists 2nd through 4th Gen EPYC and Instinct MI300A explicitly, so GPU compute nodes are in scope alongside general-purpose servers. AMD rates it 7.4 local with high attack complexity: the chained SPI-write precondition is doing real work, and this is not exploitable on its own.

Who can reach it

Local attacker on the host who already has access to a second vulnerability permitting writes to SPI flash. AMD scores it PR:N with high attack complexity; there is no remote or network path.

What to do

Apply the AGESA-based BIOS update your server OEM ships for AMD-SB-7009 - AMD publishes the fixed AGESA version per processor generation, but the flashable image comes from the platform vendor, and the fixed AGESA differs across 2nd/3rd/4th Gen EPYC and MI300A. Cost is a firmware flash with the node out of service and a full power cycle; MI300A nodes have to be drained of GPU workloads first, which is the expensive part on a busy fleet. Check the bulletin for your exact model before scheduling, since not every SKU shares a release date.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.