Database/Control plane, storage & DevOps
AMD - overlap between segmented reverse map table (RMP) and SMM memory: Improper handling of overlap between the
Impact
Improper handling of overlap between the segmented RMP and System Management Mode memory lets a privileged attacker corrupt or partially infer SMM memory. SMM is the most privileged execution context on x86 - above the hypervisor - so reaching it from the RMP path is both a route to total platform control and, in the inference direction, a leak out of the one context nothing else can inspect.
Who can reach it
Local, privileged attacker on a platform using segmented RMP (large-memory SEV-SNP configurations).
What to do
Fixed in AMD firmware/AGESA, delivered as an OEM SBIOS package with **one to six months of OEM lag** and a drained-node power cycle. Because it touches the SEV-SNP trust boundary, refresh VCEK certificates and update tenant attestation policy after the TCB version moves. Segmented RMP is used on very large memory configurations - exactly the shape of an AI training host - so do not assume this is an edge case on a GPU fleet.
References
Related entries
- Motherboards from ASRock and its subsidiaries ASRockRack and ASRockInd built on Intel 500-series chipsetsCVE-2025-14304 · Motherboards from ASRock and its subsidiaries ASRockRack and ASRockInd built on Intel 500-series chipsetsMedium
- Argo CD: Secret values exposed in error messages and the diff view when an invalid Secret is syncedCVE-2025-23216 · Argo CDMedium
- Grafana Enterprise: SAML responses skip InResponseTo validation, allowing assertion replayCVE-2026-12704 · Grafana Enterprise SAML authentication (InResponseTo validation)Medium
- Grafana: unsanitized alert generatorURL runs attacker JavaScript in a viewing user's sessionCVE-2026-17033 · Grafana OSS (Alert Details 'See source' link, alert.generatorURL rendering)Medium
- GitLab CE/EE: Terraform state upload parameters let a project user read server files or DoS the instanceCVE-2026-3855 · GitLab CE/EE (Terraform state upload parameter validation)Medium
- Volcano (admission webhook server, unbounded HTTP request body): The Volcano webhook server accepts request bodies ofCVE-2026-44247 · Volcano (admission webhook server, unbounded HTTP request body)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.