Database/Firmware, BMC & network fabric
AMD Secure Processor - cryptographic key usage control: Once an attacker has arbitrary code execution inside the ASP
Impact
Once an attacker has arbitrary code execution inside the ASP, weak key-usage controls let them extract the ASP's cryptographic keys rather than merely using them. Extracted platform keys are portable: they can be used off-box to forge attestation material or decrypt data long after you have re-imaged the node, so this turns a contained firmware compromise into a lasting one.
Who can reach it
Local, and requires having already achieved code execution in the ASP - it is a privilege-amplifier chained behind one of the other ASP bugs, not a standalone entry point.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Because this sits inside the SEV-SNP trust boundary, the update also moves the platform's reported TCB version: after patching you must refresh VCEK certificates from AMD's KDS and update whatever attestation policy your tenants (or your own confidential-VM control plane) pin against, or every guest launch will start failing validation. If you have reason to believe a node's ASP was compromised, patching does not undo key extraction - the platform keys must be considered burned and the node's attestation identity retired.
References
Related entries
- Intel TDX: insufficient verification of data authenticity in the ring 0 interface leaks trust-domain dataCVE-2025-31356 · Intel TDX (hypervisor-facing ring 0 interface)Medium
- Caliptra Core ROM: TOCTOU in update-reset lets compromised MCU firmware bypass secure boot silentlyCVE-2026-11835 · Caliptra Core ROM (UpdateResetFlow staging-address validation)Medium
- Intel processors (indirect branch prediction): Spectre v2: an attacker trains the indirect branch predictor so that aCVE-2017-5715 · Intel processors (indirect branch prediction)Medium
- Intel processors (bounds check bypass): Spectre v1: speculative execution past a bounds check lets an attacker readCVE-2017-5753 · Intel processors (bounds check bypass)Medium
- Intel processors (rogue data cache load): Meltdown: unprivileged code reads kernel memory - and on affected partsCVE-2017-5754 · Intel processors (rogue data cache load)Medium
- Intel processors: speculative sampling of stale data from microarchitectural buffers (MDS)CVE-2018-12126 · Intel processors (microarchitectural data sampling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.