Database/Firmware, BMC & network fabric
AMD Secure Processor PCI driver - input validation: Improper input validation in the ASP PCI driver lets a local
Impact
Improper input validation in the ASP PCI driver lets a local attacker trigger a buffer overflow and crash the node. Practically this is availability: a tenant-adjacent process that can reach the driver can take the host down, and on a GPU node that means every co-resident training job dies with it.
Who can reach it
Local, through the ASP PCI driver interface. Not tenant-container reachable on a normally configured node - the ccp/PSP device is not handed to workload containers.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. There is also a kernel-side component (the ccp driver); take the distro kernel update as well as the BIOS, since the OEM firmware will lag.
References
Related entries
- AMD SEV firmware - RMP write during SNP initialization: A privileged attacker can write to the reverse map page duringCVE-2025-29939 · AMD SEV firmware - RMP write during SNP initializationMedium
- AMD Secure Processor PCI driver - use-after-free: A use-after-free reachable through the ASP PCI driverCVE-2025-48521 · AMD Secure Processor PCI driver - use-after-freeMedium
- IBM Power Systems FSP: authenticated admin can force a persistent degraded operating modeCVE-2026-16938 · IBM Power Systems Firmware (FSP privileged system configuration controls)Medium
- Arista EOS: crafted password creates orphan sessions until logins are exhaustedCVE-2026-19641 · Arista EOS password authentication (session handling)Medium
- Arista EOS: gNSI Authz Rotate can activate the in-flight authorization policyCVE-2026-73445 · Arista EOS gNSI Authz Rotate RPCMedium
- Arista EOS: loose uRPF fails to drop some traffic it should verifyCVE-2026-73469 · Arista EOS loose uRPF filteringMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.