Database/Kernel, userspace & hypervisor
AMD SEV-ES (CacheWarp): CacheWarp: INVD lets a malicious hypervisor revert SEV-ES guest memory writes, breaking guest
Impact
CacheWarp: INVD lets a malicious hypervisor revert SEV-ES guest memory writes, breaking guest integrity and enabling auth bypass inside the VM
Who can reach it
Malicious/compromised host against a tenant confidential VM
What to do
Microcode/AGESA update + reboot. Undermines the trust story of any SEV-based confidential GPU-VM offering - must be reflected in attestation policy, not just patching
Fleet impact
How widespread
common - SEV-SNP is the CPU-side TEE that anchors "confidential GPU" offerings on EPYC Naples/Rome/Milan hosts
Cost to remediate
microcode+reboot for Milan; Naples/Rome are effectively unpatchable-mitigate-only, so affected nodes must be retired from any confidential-compute SKU
Why it hits the whole fleet
Breaks the integrity guarantee of confidential VMs from a malicious hypervisor - the exact threat model a neocloud invokes when it tells a customer their weights are safe from the operator.
References
Related entries
- Linux kernel (drivers/pci): When the kernel coalesces two adjacent host-bridge apertures it invalidates the absorbedCVE-2023-53814 · Linux kernel (drivers/pci)Medium
- AMD SEV-SNP (BadRAM): BadRAM: improper validation of DIMM SPD metadata lets an attacker with physical access or ring0CVE-2024-21944 · AMD SEV-SNP (BadRAM)Medium
- OpenSSL QUIC: missing connection-level flow control lets a peer force ~100MB of heap per connectionCVE-2026-75804 · OpenSSL QUIC stack (connection-level flow control)Medium
- OpenSSL CMP client: NULL dereference when revoking a certificate by PKCS#10 CSRCVE-2026-75805 · OpenSSL CMP client (revocation-by-CSR response handling)Medium
- libuser: direct /etc/passwd rewrites can corrupt the account database and chain to local rootCVE-2015-3246 · libuser / usermode userhelper (/etc/passwd modification on RHEL)Medium
- Linux KVM/SVM - missing sev_decommission in sev_receive_start: KVM failed to DECOMMISSION the current SEV contextCVE-2021-47389 · Linux KVM/SVM - missing sev_decommission in sev_receive_startMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.