Database/Firmware, BMC & network fabric
AMD SEV firmware - RMP protection bypass: An access-control failure in SEV firmware lets a malicious hypervisor bypass
Impact
An access-control failure in SEV firmware lets a malicious hypervisor bypass reverse-map table protections and break SEV-SNP guest memory integrity. The RMP is the single structure standing between a hostile host and a confidential guest's pages; a firmware-level bypass of it means the isolation you are selling is not enforced.
Who can reach it
Malicious hypervisor - host-privileged.
What to do
Fixed in AMD SEV firmware / AGESA and reaches you as an OEM SBIOS package - AMD hands AGESA to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before shipping BIOS. **Budget one to six months of OEM lag**, longer on older platforms and sometimes never on end-of-support SKUs. Applying it means draining the host and doing a full power cycle. Because the fix moves the platform's reported SEV-SNP TCB version, you must also pull fresh VCEK certificates from AMD's Key Distribution Service and update any attestation policy your tenants pin - otherwise guests will start failing launch validation the moment the BIOS lands. Some SEV firmware can alternatively be staged from linux-firmware (amd/amd_sev_*.sbin) and committed via the ccp driver at boot, which is faster than waiting on BIOS - check whether your platform supports firmware hot-load before assuming the OEM is the only route.
References
Related entries
- AMD SEV firmware - improper initialization corrupting RMP-covered memory: An initialization defect in SEV firmware letsCVE-2025-29952 · AMD SEV firmware - improper initialization corrupting RMP-covered memoryMedium
- GRUB2 TPM auto-unlock: forced rescue mode leaves the LUKS volume decrypted with the key still in memoryCVE-2025-4382 · GRUB2 with TPM-based LUKS auto-decryption (rescue mode key retention)Medium
- AMD Secure Processor firmware - MMIO routing lock (Zen 5): A missing lock check in ASP firmware on some Zen 5 partsCVE-2025-54510 · AMD Secure Processor firmware - MMIO routing lock (Zen 5)Medium
- Arista DANZ Monitoring Fabric: crafted file in an upgrade ISO bypasses image signature validationCVE-2025-54549 · Arista DANZ Monitoring Fabric (upgrade image validation)Medium
- Linux kernel (drivers/vfio/pci/mlx5): Migration and dirty-tracking state flags for an mlx5 VF were packed into sharedCVE-2026-64472 · Linux kernel (drivers/vfio/pci/mlx5)Medium
- TPM 2.0: timing side channel in RSA OAEP decryption can expose TPM-managed key material and forge attestationsCVE-2026-6727 · TPM 2.0 reference implementation (RSA OAEP decryption timing)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.