GPU VulnDB

Database/Firmware, BMC & network fabric

AMD Secure Processor - XGMI Trusted Agent (type confusion): MULTI-TENANT ISOLATION: Type confusion in the ASP's XGMI

CVE-2023-31323Firmware, BMC & network fabriccurated

Impact

MULTI-TENANT ISOLATION: Type confusion in the ASP's XGMI Trusted Agent means a malformed argument is interpreted as the wrong kind of object, producing a memory-safety violation inside the secure processor. On a multi-GPU Instinct node this is a path from host-privileged code to controlling the trusted agent that governs the GPU interconnect - the highest-scoring of the XGMI pair at 8.4.

Who can reach it

Local, host-privileged, on multi-GPU XGMI-connected platforms.

What to do

Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Same campaign as the XGMI TOCTOU issue - patch both in one OEM BIOS pass on MI-series nodes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.