Database/Firmware, BMC & network fabric
AMD SEV firmware - ASID range enforcement between SEV-ES and SEV-SNP guests: A malicious hypervisor can launch a SEV-ES
Impact
A malicious hypervisor can launch a SEV-ES guest using an ASID from the range reserved for SEV-SNP guests. ASIDs key the memory encryption, so overlapping the ranges lets a weaker-protected ES guest sit where an SNP guest's protections were assumed - a partial confidentiality loss for the SNP tenant. The interesting part is that the attack uses a legitimate hypervisor operation with an out-of-range parameter rather than any memory-safety bug.
Who can reach it
Requires hypervisor privilege and the ability to launch guests - i.e. the cloud operator or anyone who compromises the control plane.
What to do
Fixed in AMD SEV firmware / AGESA and reaches you as an OEM SBIOS package - AMD hands AGESA to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before shipping BIOS. **Budget one to six months of OEM lag**, longer on older platforms and sometimes never on end-of-support SKUs. Applying it means draining the host and doing a full power cycle. Because the fix moves the platform's reported SEV-SNP TCB version, you must also pull fresh VCEK certificates from AMD's Key Distribution Service and update any attestation policy your tenants pin - otherwise guests will start failing launch validation the moment the BIOS lands. Some SEV firmware can alternatively be staged from linux-firmware (amd/amd_sev_*.sbin) and committed via the ccp driver at boot, which is faster than waiting on BIOS - check whether your platform supports firmware hot-load before assuming the OEM is the only route.
References
Related entries
- Broadcom NetXtreme-E network adapter firmware: The lower-severity half of the same Positive Technologies NetXtreme-ECVE-2025-56548 · Broadcom NetXtreme-E network adapter firmwareMedium
- Entrust nShield HSM: BIOS setup menu has no password, so physical access allows boot configuration changesCVE-2025-59704 · Entrust nShield Connect XC / nShield 5c / nShield HSMi (BIOS setup menu)Medium
- AMD Secure Processor TEE SOC driver - SR-IOV GFX firmware load command: A malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FWCVE-2025-66664 · AMD Secure Processor TEE SOC driver - SR-IOV GFX firmware load commandMedium
- Intel TDX Guest software: incorrect calculation allows privilege escalation inside the trust domainCVE-2026-20763 · Intel TDX Guest software (guest-side TDX components before 0.3.1)Medium
- Intel TDX Guest software: incorrect comparison lets a privileged local actor escalate inside a TD guestCVE-2026-20765 · Intel TDX Guest software (ring 3 user applications)Medium
- Dell OpenManage Enterprise: low-privileged user can inject script into the console and expose informationCVE-2026-54793 · Dell OpenManage Enterprise (web console cross-site scripting)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.