Database/Firmware, BMC & network fabric
AMD Secure Processor (ASP) bootloader - buffer overflow: A buffer overflow in the ASP bootloader gives an attacker a
Impact
A buffer overflow in the ASP bootloader gives an attacker a memory overwrite in the secure processor's boot path, ending in privilege escalation and arbitrary code execution below the OS. Anything the ASP protects on that node - SEV keys, fTPM, boot measurement - is then attacker-controlled, and the foothold persists across OS reinstalls.
Who can reach it
Local. Needs the ability to influence what the bootloader parses, i.e. SPI ROM write access or a subverted firmware update path.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Lock down SPI ROM writes and platform BIOS update authentication as the interim control; there is no OS-level mitigation for bootloader code.
References
Related entries
- Linux x86/sev - Secure TSC frequency calculation (TSC_FACTOR): Secure TSC is how an SEV-SNP guest gets a timebaseCVE-2025-38508 · Linux x86/sev - Secure TSC frequency calculation (TSC_FACTOR)High
- IBM Power Systems firmware: guest-partition root can write NVRAM that crashes the host firmware boot stageCVE-2026-17042 · IBM Power Systems host firmware (OpenPOWER NVRAM parsing)High
- Linux kernel (drivers/infiniband/hw/irdma): Queue-depth arithmetic was done in 32 bits, so a tenant passing a hugeCVE-2026-31491 · Linux kernel (drivers/infiniband/hw/irdma)High
- Dell OMSA: externally controlled class selection bypasses a protection mechanismCVE-2026-66269 · Dell OpenManage Server Administrator (unsafe reflection)High
- Dell OMSA: local low-privileged user reads sensitive information beyond the agent's scopeCVE-2026-80356 · Dell OpenManage Server Administrator (sensitive information exposure)High
- Dell OMSA: hard-coded credentials give an unauthenticated remote attacker accessCVE-2026-81440 · Dell OpenManage Server Administrator (hard-coded credentials)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.