Database/Firmware, BMC & network fabric
AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena): SNP firmware fails to restrict where a hypervisor-driven
Impact
SNP firmware fails to restrict where a hypervisor-driven write can land, letting a malicious host overwrite a confidential guest's memory or the UMC seed that derives that guest's memory encryption key. Overwriting guest memory defeats the integrity half of SNP outright; overwriting the UMC seed lets the operator choose the key material protecting a tenant. This is the highest-severity item in the AMD-SB-3011 batch and it is squarely an operator-versus-tenant break - the exact threat model a customer pays the SNP premium for.
Who can reach it
Malicious hypervisor / host root issuing SNP firmware commands against a running confidential guest. Local, high privilege.
What to do
Two options per AMD-SB-3011: hot-loadable SEV firmware (1.37.14 hex on Milan, 1.37.24 on Genoa) which does NOT require a reboot, or a full Platform Initialization / BIOS flash (MilanPI 1.0.0.D, GenoaPI 1.0.0.C) which does. Take the SEV firmware path first to close the window without draining training jobs, then fold the PI update into your next maintenance cycle. Fixing it moves the SNP TCB version above 0x16 (Milan) / 0x15 (Genoa), which changes every attestation report the host issues - tenants' verifiers must be updated to accept the new TCB or their attestation will start failing.
References
Related entries
- Intel reference platforms (Seamless Firmware Updates): A race condition in the seamless firmware update mechanism letsCVE-2024-23599 · Intel reference platforms (Seamless Firmware Updates)High
- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-39585 · Dell SmartFabric OS10 (hard-coded password)High
- Insyde InsydeH2O (VariableRuntimeDxe, SecureBootHandler): The Secure Boot variable handler bounds-checks incoming dataCVE-2024-52880 · Insyde InsydeH2O (VariableRuntimeDxe, SecureBootHandler)High
- Intel Xeon 6 with TDX (protected memory range handling): Improper handling of overlap between protected memory rangesCVE-2025-22889 · Intel Xeon 6 with TDX (protected memory range handling)High
- IBM Power Systems Firmware: BMC/FSP root can read and disrupt host processor state across all partitionsCVE-2026-17063 · IBM Power Systems Firmware (BMC/FSP-to-host interface, processor state)High
- TPM 2.0 reference code: leak lets a privileged local user obtain a CA credential for a falsified TPM keyCVE-2026-6726 · TCG TPM 2.0 reference code (attestation credential handling, TCG VRT0010)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.