Database/Firmware, BMC & network fabric
AMD SEV firmware - incomplete memory cleanup (AMD-SB-3003): Incomplete memory cleanup in the SEV firmware allows
Impact
Incomplete memory cleanup in the SEV firmware allows corruption of guest private memory. The recurring pattern in this database - firmware that does not scrub or fully release state between uses - applied to the memory of confidential guests, where the whole product claim is that nobody but the guest can touch it.
Who can reach it
Local, privileged, on a host running SEV guests.
What to do
Fixed in AMD PI/AGESA firmware and delivered only as an OEM SBIOS package - AMD ships the PI drop to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before releasing BIOS. **Budget one to six months of OEM lag**, and note that several CVEs in this batch are marked 'no fix planned' on Naples (EPYC 7001) - for those the only remediation is retiring the hardware. Applying it means cordon, drain and a full power cycle per node; there is no driver reload, no live patch and no VBIOS step. Because this touches the SEV-SNP trust boundary, the update moves the platform TCB version: refresh VCEK certificates from AMD's KDS and update tenant attestation policy, or confidential guest launches will fail immediately after the BIOS lands.
References
Related entries
- Arm Trusted Firmware-A before v2.10, SDEI service (sdei_interrupt_bind SMC handler): An SMC argument from the normalCVE-2023-49100 · Arm Trusted Firmware-A before v2.10, SDEI service (sdei_interrupt_bind SMC handler)Medium
- AMD Power Management Firmware (SMU) - array index validation: An unvalidated array index in AMD's power managementCVE-2024-21970 · AMD Power Management Firmware (SMU) - array index validationMedium
- GRUB2 (dump command lockdown): The dump command was not disabled under Secure Boot lockdown, letting a privileged userCVE-2025-1118 · GRUB2 (dump command lockdown)Medium
- Solidigm DC SSD firmware - unauthorized access to a LOCKED storage device via improper resource management: An attackerCVE-2025-12896 · Solidigm DC SSD firmware - unauthorized access to a LOCKED storage device via improper resource managementMedium
- Juniper Junos OS kernel: Improper isolation in the Junos kernel lets a local attacker with shell access injectCVE-2025-21590 · Juniper Junos OS kernelMedium
- Lenovo XClarity Controller (LDAP mode): Read-only authentication bypass when XCC is in LDAP-only authentication modeCVE-2021-3956 · Lenovo XClarity Controller (LDAP mode)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.