GPU VulnDB

Database/Control plane, storage & DevOps

AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014): MULTI-TENANT ISOLATION: The BadRAM SPD-aliasing

CVE-2024-36354Control plane, storage & DevOpsBadRAM (SMM variant)curated

Impact

MULTI-TENANT ISOLATION: The BadRAM SPD-aliasing technique aimed at System Management Mode rather than at SEV. By lying about a DIMM's size in its serial-presence-detect chip, an attacker creates physical address aliases that let ring-0 code reach into SMRAM and execute at SMM - the level above the hypervisor. Where the SEV-facing BadRAM breaks confidential VMs, this one breaks the platform outright, and it lands beneath every detection tool you run.

Who can reach it

Either brief physical access to the DIMM's SPD chip (the published rig is a ~$10 microcontroller), or - crucially - **ring-0 on a host that has non-compliant DIMMs with unlocked SPD, which needs no physical access at all**. That second path is what makes this a real datacenter concern rather than an evil-maid curiosity.

What to do

Fixed in AMD PI/AGESA firmware and delivered only as an OEM SBIOS package - AMD ships the PI drop to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before releasing BIOS. **Budget one to six months of OEM lag**, and note that several CVEs in this batch are marked 'no fix planned' on Naples (EPYC 7001) - for those the only remediation is retiring the hardware. Applying it means cordon, drain and a full power cycle per node; there is no driver reload, no live patch and no VBIOS step. The fix adds a boot-time alias-detection scan. Beyond patching, change procurement: specify SPD-lockable DIMMs and verify the lock is actually set, because on non-compliant modules a remote ring-0 attacker reaches this without ever entering your building. Patch this together with the SEV-facing BadRAM CVE - they ship in the same firmware wave.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.