Database/Firmware, BMC & network fabric
AMD CPU microcode patch loading - improper cleanup: Improper cleanup during microcode patch loading gives a local
Impact
Improper cleanup during microcode patch loading gives a local administrator another route to load malicious CPU microcode, costing integrity of x86 instruction execution itself. This is the same category of failure as EntrySign and lands in the same place: the CPU can be made to lie, and everything built on top of it - SEV-SNP guest isolation included - inherits the lie.
Who can reach it
Local, administrator privilege. Reboot clears a loaded implant, but the attacker who has admin can simply reload it every boot.
What to do
Fixed by an AMD microcode patch. Two delivery routes, and the difference matters: the linux-firmware amd-ucode blobs load early at boot (initramfs) and need only a reboot, while the durable fix is the microcode embedded in the OEM SBIOS/AGESA package, which carries the usual one-to-six-month OEM lag and a full power cycle. **For confidential computing you need the SBIOS route**: microcode late-loaded by the OS is not part of what SEV-SNP attests, so a guest checking the attestation report cannot tell the fix is present. AMD does not support late-loading microcode on a running EPYC host - treat this as reboot-required. After patching, expect the reported TCB version to change and plan the VCEK certificate refresh accordingly.
References
Related entries
- Supermicro BMC firmware validation logic on the X12STW-F motherboard: An attacker with administrative reach to the BMCCVE-2025-12006 · Supermicro BMC firmware validation logic on the X12STW-F motherboardHigh
- Intel CSME firmware (TOCTOU): A time-of-check/time-of-use race in CSME firmware lets a privileged local user escalateCVE-2025-20037 · Intel CSME firmware (TOCTOU)High
- Intel Xeon processor firmware (SGX enabled): Improper buffer restrictions in Xeon firmware on SGX-enabled parts, givingCVE-2025-20053 · Intel Xeon processor firmware (SGX enabled)High
- Intel Xeon 6 memory subsystem (with SGX or TDX): An out-of-bounds write in the Xeon 6 memory subsystem reachable whenCVE-2025-26403 · Intel Xeon 6 memory subsystem (with SGX or TDX)High
- Intel Xeon 6 DDRIO configuration (with SGX or TDX): An improperly implemented security check in DDRIO configuration onCVE-2025-32086 · Intel Xeon 6 DDRIO configuration (with SGX or TDX)High
- AMI AptioV UEFI BIOS: Improper handling of insufficient permissions in the BIOS lets a low-privileged local userCVE-2025-58770 · AMI AptioV UEFI BIOSHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.