Database/Control plane, storage & DevOps
AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016): Insufficient RMP checking on IOMMU host buffer
Impact
Insufficient RMP checking on IOMMU host buffer access produces an out-of-bounds write. This is the most operationally expensive item in the RMP family, because of what fixing it costs rather than what it does.
Who can reach it
Privileged attacker with hypervisor control, via IOMMU host buffer operations.
What to do
Fixed in AMD PI/AGESA firmware and delivered only as an OEM SBIOS package - AMD ships the PI drop to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before releasing BIOS. **Budget one to six months of OEM lag**, and note that several CVEs in this batch are marked 'no fix planned' on Naples (EPYC 7001) - for those the only remediation is retiring the hardware. Applying it means cordon, drain and a full power cycle per node; there is no driver reload, no live patch and no VBIOS step. Because this touches the SEV-SNP trust boundary, the update moves the platform TCB version: refresh VCEK certificates from AMD's KDS and update tenant attestation policy, or confidential guest launches will fail immediately after the BIOS lands. **This one needs more than a BIOS flash**: AMD requires the firmware update, an OS update, *and* a full SNP guest shutdown and platform re-initialization. In practice that means draining every confidential VM off the host, tearing down SNP, updating, re-initializing and re-admitting - a materially longer maintenance window than the rest of the batch, and one you cannot overlap with normal rolling reboots. Plan capacity for it explicitly.
References
Related entries
- ZKTeco BioAccess IVS v3.3.1 access control platform: An unauthenticated attacker can open and close any doorCVE-2023-38958 · ZKTeco BioAccess IVS v3.3.1 access control platformMedium
- Intel Data Center GPU Flex Series - Windows driver software: Improper access control in the Flex Series Windows driverCVE-2024-43101 · Intel Data Center GPU Flex Series - Windows driver softwareMedium
- Grafana: Org Admin can read dashboard permission mappings belonging to other organizationsCVE-2026-11817 · Grafana access-control API (/api/access-control/users/permissions/search), multi-org stacksMedium
- OpenChoreo: autobuild webhook picks its provider from a caller-supplied header and accepts unsigned Bitbucket requestsCVE-2026-73840 · OpenChoreo API (POST /api/v1alpha1/autobuild webhook handler)Medium
- GitLab CE/EE: improper authorization on internal endpoints exposes credentials and tokensCVE-2026-82837 · GitLab CE/EE (internal data emission endpoints, authorization)Medium
- Ansible automation-controller: Bitbucket DC webhook ping skips HMAC check, enumerating webhook-enabled templatesCVE-2026-84717 · Red Hat Ansible Automation Platform automation-controller (Bitbucket Data Center webhook receiver)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.