Database/Firmware, BMC & network fabric
ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoC: Improper input validation in the ARM Trusted Firmware used
Impact
Improper input validation in the ARM Trusted Firmware used on AMD's Zynq UltraScale+ parts allows out-of-bounds reads and data leakage. Relevant to datacenter operators through the side door: Zynq and Versal parts show up as SmartNIC, DPU, storage-controller and management-plane silicon inside servers, so this is firmware running on your network path rather than on your compute path.
Who can reach it
Local to the device, requires privileged access to the ATF interface on the Zynq part.
What to do
Fixed in updated ARM Trusted Firmware from AMD/Xilinx. Delivery depends entirely on who integrated the part - a SmartNIC vendor, a storage OEM, your own board team - so tracing the update path is often harder than applying it. Requires a device firmware update and a reset of the affected card. Inventory which AMD/Xilinx adaptive SoCs are in your servers; most operators cannot answer that question, which is the real finding.
References
Related entries
- AMD Secure Processor bootloader - legacy recovery mode: Insufficient input sanitisation in the ASP bootloader's legacyCVE-2025-29949 · AMD Secure Processor bootloader - legacy recovery modeMedium
- Junos OS Evolved: OS command injection in the CLI lets a low-privileged operator escalateCVE-2025-60006 · Juniper Junos OS Evolved (CLI command option handling)Medium
- Intel SGX SDK (Edger8r generated code, side channel): Edger8r generated bridge code that was susceptible to a sideCVE-2018-3626 · Intel SGX SDK (Edger8r generated code, side channel)Medium
- AMD processors - PREFETCH instruction timing and power side channel: Timing and power measurements around the x86CVE-2021-26318 · AMD processors - PREFETCH instruction timing and power side channelMedium
- AMD processors with SMT - speculative execution across SMT mode switch: With SMT enabled, certain AMD processorsCVE-2022-27672 · AMD processors with SMT - speculative execution across SMT mode switchMedium
- Intel processors (return stack buffer alternate prediction): When the return stack buffer underflows, the processorCVE-2022-28693 · Intel processors (return stack buffer alternate prediction)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.