Database/Firmware, BMC & network fabric
AMD Secure Processor firmware - MMIO routing lock (Zen 5): A missing lock check in ASP firmware on some Zen 5 parts
Impact
A missing lock check in ASP firmware on some Zen 5 parts lets a locally authenticated administrator alter MMIO routing after the point where it should have been frozen. Redirecting MMIO means pointing a device's window somewhere it should not go - which is how a host administrator reaches into a confidential guest's memory despite SEV-SNP.
Who can reach it
Local, administrative privilege on the host. Affects Zen 5 (Turin / EPYC 9005) generation parts.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Because this sits inside the SEV-SNP trust boundary, the update also moves the platform's reported TCB version: after patching you must refresh VCEK certificates from AMD's KDS and update whatever attestation policy your tenants (or your own confidential-VM control plane) pin against, or every guest launch will start failing validation.
References
Related entries
- Arista DANZ Monitoring Fabric: crafted file in an upgrade ISO bypasses image signature validationCVE-2025-54549 · Arista DANZ Monitoring Fabric (upgrade image validation)Medium
- Linux kernel (drivers/vfio/pci/mlx5): Migration and dirty-tracking state flags for an mlx5 VF were packed into sharedCVE-2026-64472 · Linux kernel (drivers/vfio/pci/mlx5)Medium
- TPM 2.0: timing side channel in RSA OAEP decryption can expose TPM-managed key material and forge attestationsCVE-2026-6727 · TPM 2.0 reference implementation (RSA OAEP decryption timing)Medium
- Arista EOS: RADIUS proxy suppresses CoA and Disconnect-Requests for local 802.1X sessionsCVE-2026-73449 · Arista EOS (RADIUS proxy with dynamic authorization / 802.1X CoA)Medium
- Arista EOS (security ACL vs NAT rule interaction): A security ACL drop rule is bypassed when a NAT ACL permit ruleCVE-2021-28511 · Arista EOS (security ACL vs NAT rule interaction)Medium
- AMI MegaRAC SPx 12 (BMC default TLS certificate): The BMC ships with a hard-coded default TLS certificate, so HTTPSCVE-2021-4228 · AMI MegaRAC SPx 12 (BMC default TLS certificate)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.