Database/Control plane, storage & DevOps
AMD NBIO register lock bits - MMIO routing configuration: The sibling of the SMN issue: unprotected NBIO lock bits let
Impact
The sibling of the SMN issue: unprotected NBIO lock bits let a local administrator rewrite MMIO routing configuration and break SEV-SNP guest integrity. The host operator can point address windows at confidential guest memory that the RMP was supposed to fence off.
Who can reach it
Local, host administrator privilege.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Because this sits inside the SEV-SNP trust boundary, the update also moves the platform's reported TCB version: after patching you must refresh VCEK certificates from AMD's KDS and update whatever attestation policy your tenants (or your own confidential-VM control plane) pin against, or every guest launch will start failing validation. Same OEM BIOS package as the SMN lock-bit issue; do not patch one and leave the other.
References
Related entries
- ansible-runner: streamed archive extraction follows symlinks and writes outside the target directoryCVE-2026-103754 · ansible-runner (unstream_dir() in the transmit/worker protocol)Medium
- DMTF libspdm - SPDM Requester timeout handling: A libspdm Requester stores the Responder's CTExponentCVE-2023-32690 · DMTF libspdm - SPDM Requester timeout handlingMedium
- Dell OpenManage Enterprise (path traversal): An unauthenticated remote attacker reads files from the OME serverCVE-2024-25944 · Dell OpenManage Enterprise (path traversal)Medium
- Elastic Metricbeat: oversized Prometheus remote_write request drives an unbounded allocation and kills the beatCVE-2026-26931 · Elastic Metricbeat (Prometheus remote_write HTTP handler)Medium
- AMD Zen 1 / Zen 2 / Zen 3 - execution unit scheduler queue contention (SMT): AMD's split scheduler design gives eachCVE-2021-46778 · AMD Zen 1 / Zen 2 / Zen 3 - execution unit scheduler queue contention (SMT)Medium
- IBM Spectrum Scale / GPFS node file access path: An unprivileged but authenticated user on a GPFS node reads arbitraryCVE-2018-1723 · IBM Spectrum Scale / GPFS node file access pathMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.