Database/Control plane, storage & DevOps
AMD IOMMU register interface - ASP coherency: Improper access control on the IOMMU register interface lets a privileged
Impact
Improper access control on the IOMMU register interface lets a privileged attacker force non-coherent accesses by the AMD Secure Processor. Incoherent reads by the security engine mean it can be shown stale or inconsistent data - a subtle way to make the ASP act on something other than what is actually in memory.
Who can reach it
Local, privileged, via the IOMMU register interface.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string.
References
Related entries
- AGESA Boot Loader (ABL) - SPI ROM header input validation (AMD-SB-3003): The AGESA Boot Loader does not properlyCVE-2021-46772 · AGESA Boot Loader (ABL) - SPI ROM header input validation (AMD-SB-3003)Low
- Redis: Lua environment weakness lets a user inject code that runs with another Redis user's privilegesCVE-2022-24735 · RedisLow
- Slurm (X11 forwarding, xauth magic-cookie setup): Slurm shells out to xauth to install a user's X11 magic cookie, andCVE-2020-27746 · Slurm (X11 forwarding, xauth magic-cookie setup)Low
- Zabbix: Some setup.php steps reachable by unauthenticated usersCVE-2022-23134 · ZabbixLow
- SkyPilot (sky/users/server.py, user ID derivation from username): User IDs are derived with a weak hash of theCVE-2026-13482 · SkyPilot (sky/users/server.py, user ID derivation from username)Low
- GitLab: unauthenticated GraphQL requests can read CI/CD job traces containing secret variable valuesCVE-2026-4523 · GitLab CE/EE (GraphQL API, CI/CD job traces)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.