GPU VulnDB

Database/Kernel, userspace & hypervisor

AMD CPU (Sinkclose): Sinkclose: SMM lock bypass

CVE-2023-31315Kernel, userspace & hypervisorcurated

Impact

Sinkclose: SMM lock bypass - ring-0 attacker gains SMM execution, enabling firmware-persistent implants that survive reimaging

Who can reach it

Local ring-0 (post-kernel-escape), i.e. the second stage after any kernel privesc above

What to do

AGESA/BIOS firmware update + reboot; requires a full firmware rollout across the fleet, not a package update. Some older EPYC SKUs never got fixes

Fleet impact

How widespread

very common - AMD EPYC is a standard GPU-server host CPU and the host side of MI300 platforms; the flaw reaches back to 2006-era silicon

Cost to remediate

microcode+reboot / firmware-flash via an AGESA/BIOS update per node; AMD initially declined to patch some older Zen parts, leaving unpatchable-mitigate-only nodes in mixed fleets

Why it hits the whole fleet

A tenant (or escaped container) with kernel access reaches System Management Mode, the most privileged mode on the box, and can plant an SMM implant invisible to OS and hypervisor that survives a disk wipe.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.