Database/Control plane, storage & DevOps
AMD PCIe link handling (memory buffer bounds): A guest VM can drive the PCIe link into an out-of-bounds condition
Impact
A guest VM can drive the PCIe link into an out-of-bounds condition and deny service to the entire host. On an AI node the PCIe fabric is the load-bearing structure - GPUs, NVMe scratch, RDMA NICs all hang off it - so a link-level fault does not degrade one tenant, it takes the box down and kills every job on it. This is a guest-to-host availability break reachable from a normal VM, which is a materially different risk class from the ring 0 firmware issues elsewhere in this set.
Who can reach it
Attacker with access to a guest virtual machine - an ordinary paying tenant. Network-adjacent attack vector per AMD's scoring, low privilege required.
What to do
Firmware update per AMD-SB-4013 from the OEM; BIOS flash and reboot. In the meantime the practical control is blast-radius management rather than prevention: do not co-locate high-value long-running training jobs with untrusted short-lived tenants on the same PCIe complex, and make sure checkpointing intervals assume the node can vanish. Note this bulletin targets client and embedded platform audits, so confirm applicability to your specific EPYC or Instinct SKUs with your vendor before planning a fleet-wide flash.
References
Related entries
- OpenStack Swift: S3API does not strip X-Copy-From, allowing cross-tenant object readsCVE-2026-71192 · OpenStack Swift S3API middleware (X-Copy-From header handling with s3_acl=true)Medium
- AMD NBIO register lock bits - MMIO routing configuration: The sibling of the SMN issue: unprotected NBIO lock bits letCVE-2025-61971 · AMD NBIO register lock bits - MMIO routing configurationMedium
- ansible-runner: streamed archive extraction follows symlinks and writes outside the target directoryCVE-2026-103754 · ansible-runner (unstream_dir() in the transmit/worker protocol)Medium
- DMTF libspdm - SPDM Requester timeout handling: A libspdm Requester stores the Responder's CTExponentCVE-2023-32690 · DMTF libspdm - SPDM Requester timeout handlingMedium
- Dell OpenManage Enterprise (path traversal): An unauthenticated remote attacker reads files from the OME serverCVE-2024-25944 · Dell OpenManage Enterprise (path traversal)Medium
- Elastic Metricbeat: oversized Prometheus remote_write request drives an unbounded allocation and kills the beatCVE-2026-26931 · Elastic Metricbeat (Prometheus remote_write HTTP handler)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.