Database/Firmware, BMC & network fabric
AMD CPU microcode - bound check: An improper bound check inside AMD CPU microcode lets a malicious **guest** write into
Impact
An improper bound check inside AMD CPU microcode lets a malicious **guest** write into host memory. This is a straight VM-escape primitive expressed in silicon microcode rather than in the hypervisor: the tenant does not need a QEMU or KVM bug, the CPU itself lets the write through. Once a guest can write host memory the host is compromised, and from there every other VM on the box.
Who can reach it
From inside a guest VM - no host privilege required. That makes this materially more dangerous operationally than the local-admin microcode issues: your tenants are the attackers in the threat model.
What to do
Fixed by an AMD microcode patch. Two delivery routes, and the difference matters: the linux-firmware amd-ucode blobs load early at boot (initramfs) and need only a reboot, while the durable fix is the microcode embedded in the OEM SBIOS/AGESA package, which carries the usual one-to-six-month OEM lag and a full power cycle. **For confidential computing you need the SBIOS route**: microcode late-loaded by the OS is not part of what SEV-SNP attests, so a guest checking the attestation report cannot tell the fix is present. AMD does not support late-loading microcode on a running EPYC host - treat this as reboot-required. After patching, expect the reported TCB version to change and plan the VCEK certificate refresh accordingly. Prioritise this above the local-admin microcode issues on any node that runs untrusted guest VMs - the attacker prerequisite here is simply 'is a tenant'.
References
Related entries
- AMD Secure Processor - privilege check on write path: The ASP accepts an input value and performs a writeCVE-2025-54511 · AMD Secure Processor - privilege check on write pathMedium
- Arista EOS: crafted packet terminates the MACsec process and disrupts dataplane trafficCVE-2025-7048 · Arista EOS (MACsec process)Medium
- Arista EOS: VRRPv2 IP-AH authentication bypass lets an attacker claim the virtual router master roleCVE-2026-73444 · Arista EOS VRRPv2 IP Authentication Header (IP-AH) authenticationMedium
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-002-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-004-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
- AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003): A stack overrun in the ASP Secure OS trustedCVE-2021-46746 · AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.