Database/Kernel, userspace & hypervisor
AMD SEV-SNP (BadRAM): BadRAM: improper validation of DIMM SPD metadata lets an attacker with physical access or ring0
Impact
BadRAM: improper validation of DIMM SPD metadata lets an attacker with physical access or ring0 on a non-compliant DIMM overwrite guest memory and forge SNP attestation
Who can reach it
Physical access / compromised host firmware against a confidential tenant VM
What to do
AGESA/BIOS firmware update + reboot, plus DIMM SPD lockdown at the supply-chain level. Cannot be fixed in software - a genuine constraint on any "we cannot see your data" confidential-GPU claim
Fleet impact
How widespread
common - 3rd/4th-gen EPYC (Milan, Milan-X, Genoa, Bergamo, Genoa-X, Siena) hosts under GPU nodes
Cost to remediate
firmware-flash - AMD's fix validates SPD metadata at boot, so it is a BIOS/AGESA update per node; the underlying attack needs ~$10 of hardware and physical access, which colo and bare-metal-rental models do not exclude
Why it hits the whole fleet
Forges SEV-SNP attestation reports and inserts undetectable backdoors into confidential VMs, i.e. every attestation a customer verified on affected hosts is retroactively meaningless.
References
Related entries
- OpenSSL QUIC: missing connection-level flow control lets a peer force ~100MB of heap per connectionCVE-2026-75804 · OpenSSL QUIC stack (connection-level flow control)Medium
- OpenSSL CMP client: NULL dereference when revoking a certificate by PKCS#10 CSRCVE-2026-75805 · OpenSSL CMP client (revocation-by-CSR response handling)Medium
- libuser: direct /etc/passwd rewrites can corrupt the account database and chain to local rootCVE-2015-3246 · libuser / usermode userhelper (/etc/passwd modification on RHEL)Medium
- Linux KVM/SVM - missing sev_decommission in sev_receive_start: KVM failed to DECOMMISSION the current SEV contextCVE-2021-47389 · Linux KVM/SVM - missing sev_decommission in sev_receive_startMedium
- QEMU VMDK driver: a crafted image causes an out-of-bounds read leaking 12 bytes or crashing the processCVE-2026-2243 · QEMU VMDK block driver (out-of-bounds read while parsing the image)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi updated the domain's I/O page-table mode before running the code that freesCVE-2022-48904 · Linux kernel (drivers/iommu/amd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.