Database/Firmware, BMC & network fabric
AMD SEV firmware - SEV-ES guest attacking an SNP guest: Coarse access-control granularity in SEV firmware lets a
Impact
Coarse access-control granularity in SEV firmware lets a privileged attacker create a SEV-ES guest positioned to attack an SNP guest, costing the SNP guest confidentiality. The pattern is worth internalising: mixing SEV generations on one host means the weakest guest type in the mix can become the attack platform against the strongest.
Who can reach it
Requires the ability to launch guests with chosen SEV parameters - the operator or a compromised control plane.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string. This sits inside the SEV-SNP trust boundary, so the update moves the platform's reported TCB version: refresh VCEK certificates from AMD's KDS and update any attestation policy your tenants pin, or confidential guest launches will start failing right after the BIOS lands. Interim control: do not co-schedule legacy SEV/SEV-ES guests alongside SEV-SNP guests on the same host. Pinning confidential-tier workloads to SNP-only hosts removes the attack platform entirely and costs you scheduling flexibility rather than a maintenance window.
References
Related entries
- AMD Secure Processor kernel - DRAM mapping into protected areas (AMD-SB-3003): An access-control gap in the ASP kernelCVE-2021-26387 · AMD Secure Processor kernel - DRAM mapping into protected areas (AMD-SB-3003)Low
- Intel SGX SDK (Edger8r code generator): The Edger8r tool generates the trusted/untrusted bridge code for enclavesCVE-2025-32004 · Intel SGX SDK (Edger8r code generator)Low
- Intel SGX DCAP for Windows: Input-validation flaw in the Windows DCAP components allowing local information disclosureCVE-2023-42776 · Intel SGX DCAP for WindowsLow
- AMD processors - speculative inference of control registers despite UMIP: Part of the Transient Scheduler Attacks batchCVE-2024-36348 · AMD processors - speculative inference of control registers despite UMIPLow
- AMD processors - speculative inference of TSC_AUX when reads are disabled: Sibling of the other Transient SchedulerCVE-2024-36349 · AMD processors - speculative inference of TSC_AUX when reads are disabledLow
- Hitachi VSP One Block: firmware update path does not validate the image before applying itCVE-2025-0824 · Hitachi Virtual Storage Platform One Block 23/24/26/28 (firmware update validation)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.