Database/Firmware, BMC & network fabric
AMD SEV-SNP firmware - input validation: Improper input validation in SEV-SNP lets a malicious hypervisor read or
Impact
Improper input validation in SEV-SNP lets a malicious hypervisor read or overwrite guest memory. That is the whole point of SEV-SNP defeated in one line: the host, which SNP exists to exclude, gets both read and write access to the confidential guest's pages.
Who can reach it
Malicious or compromised hypervisor. The guest need do nothing.
What to do
Fixed in AMD SEV firmware / AGESA and reaches you as an OEM SBIOS package - AMD hands AGESA to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before shipping BIOS. **Budget one to six months of OEM lag**, longer on older platforms and sometimes never on end-of-support SKUs. Applying it means draining the host and doing a full power cycle. Because the fix moves the platform's reported SEV-SNP TCB version, you must also pull fresh VCEK certificates from AMD's Key Distribution Service and update any attestation policy your tenants pin - otherwise guests will start failing launch validation the moment the BIOS lands. Some SEV firmware can alternatively be staged from linux-firmware (amd/amd_sev_*.sbin) and committed via the ccp driver at boot, which is faster than waiting on BIOS - check whether your platform supports firmware hot-load before assuming the OEM is the only route.
References
Related entries
- AMD Power Management Firmware (PMFW) - guest VM input validation causing GPU reset: Improper input validation in AMD'sCVE-2024-36346 · AMD Power Management Firmware (PMFW) - guest VM input validation causing GPU resetMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2024-39283 · Intel TDX moduleMedium
- GRUB2 (BFS filesystem parser): Integer overflow producing a heap out-of-bounds read in the BeFS parserCVE-2024-45779 · GRUB2 (BFS filesystem parser)Medium
- AMD SEV-SNP - RMP write access during SNP initialization: There is a window during SEV-SNP initialization in which anCVE-2025-0033 · AMD SEV-SNP - RMP write access during SNP initializationMedium
- Intel CSME / SPS firmware (timing side channel): An observable timing discrepancy in CSME/SPS firmware allowsCVE-2025-20067 · Intel CSME / SPS firmware (timing side channel)Medium
- Intel E810 Ethernet controller firmware: Improper input validation in E810 firmware lets a privileged local user denyCVE-2025-24296 · Intel E810 Ethernet controller firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.