Database/Control plane, storage & DevOps
AMD Versal Adaptive SoC - PLM runtime services address validation: The Platform Loader and Manager firmware on AMD
Impact
The Platform Loader and Manager firmware on AMD Versal devices does not validate addresses when executing runtime services, so a caller reaches isolated or protected memory spaces. On Versal parts the PLM is the root of trust and the isolation enforcer for the device's partitions - bypassing its address checks means crossing whatever partition boundary the design relies on, which on a multi-tenant SmartNIC or accelerator card is the tenant boundary.
Who can reach it
Local to the device, via PLM runtime service calls.
What to do
Fixed in updated PLM firmware from AMD/Xilinx, applied as a device firmware image plus a card reset. Reaches you through whoever built the card, so expect integrator lag on top of AMD's release. Track which Versal-based cards are in your fleet and who owns their firmware pipeline.
References
Related entries
- Ansible automation-controller: unvalidated system-job "days" value injects arguments into control-node awx-manageCVE-2026-84724 · Red Hat Ansible Automation Platform automation-controller (system-job launch, awx-manage argument vector)Medium
- HTCondor (condor_schedd, GSI/VOMS extension parsing): An authenticated user crashes the schedd by feeding it malformedCVE-2017-16816 · HTCondor (condor_schedd, GSI/VOMS extension parsing)Medium
- GlusterFS (dict_unserialize): A negative key length in a serialized dict makes the server read memory from elsewhere inCVE-2018-10911 · GlusterFS (dict_unserialize)Medium
- Ceph CephX authentication protocol: The CephX signature calculation can be bypassed, so an on-path attacker can alterCVE-2018-1129 · Ceph CephX authentication protocolMedium
- Intel Core and Xeon CPUs - INTEL-SA-00210: This one is availability, not confidentiality, and it is the mostCVE-2018-12207 · Intel Core and Xeon CPUs - INTEL-SA-00210Medium
- Nouveau display driver (in-tree Linux nouveau, NV117): Remote denial of service against a workstation or node runningCVE-2018-3979 · Nouveau display driver (in-tree Linux nouveau, NV117)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.