Database/Firmware, BMC & network fabric
AMD SEV firmware - improper initialization corrupting RMP-covered memory: An initialization defect in SEV firmware lets
Impact
An initialization defect in SEV firmware lets an admin-privileged attacker corrupt memory covered by the RMP, costing confidential guest integrity. Same family as the other RMP issues in this batch and shipped in the same AMD advisory wave - the recurring theme is that SNP's protections are only as good as the firmware that sets them up.
Who can reach it
Local, admin-privileged.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string. This sits inside the SEV-SNP trust boundary, so the update moves the platform's reported TCB version: refresh VCEK certificates from AMD's KDS and update any attestation policy your tenants pin, or confidential guest launches will start failing right after the BIOS lands.
References
Related entries
- GRUB2 TPM auto-unlock: forced rescue mode leaves the LUKS volume decrypted with the key still in memoryCVE-2025-4382 · GRUB2 with TPM-based LUKS auto-decryption (rescue mode key retention)Medium
- AMD Secure Processor firmware - MMIO routing lock (Zen 5): A missing lock check in ASP firmware on some Zen 5 partsCVE-2025-54510 · AMD Secure Processor firmware - MMIO routing lock (Zen 5)Medium
- Arista DANZ Monitoring Fabric: crafted file in an upgrade ISO bypasses image signature validationCVE-2025-54549 · Arista DANZ Monitoring Fabric (upgrade image validation)Medium
- Linux kernel (drivers/vfio/pci/mlx5): Migration and dirty-tracking state flags for an mlx5 VF were packed into sharedCVE-2026-64472 · Linux kernel (drivers/vfio/pci/mlx5)Medium
- TPM 2.0: timing side channel in RSA OAEP decryption can expose TPM-managed key material and forge attestationsCVE-2026-6727 · TPM 2.0 reference implementation (RSA OAEP decryption timing)Medium
- Arista EOS: RADIUS proxy suppresses CoA and Disconnect-Requests for local 802.1X sessionsCVE-2026-73449 · Arista EOS (RADIUS proxy with dynamic authorization / 802.1X CoA)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.