GPU VulnDB

Database/Firmware, BMC & network fabric

AMD Pensando ionic driver on ESXi: untrusted pointer dereference lets a guest VM read kernel and co-tenant memory

CVSS 7.2CVE-2025-62627Firmware, BMC & network fabriccurated

Impact

An untrusted pointer dereference in the ionic cloud driver gives an unprivileged VM a path to read ESXi kernel memory or the memory of other VMs sharing the host. On a DPU-offloaded GPU host that breaks the tenant boundary at the layer operators lean on most heavily: the DPU terminates the network datapath for every VM on the box, so one tenant VM reading across it can reach keys, tokens and in-flight data belonging to neighbouring workloads. AMD also notes a potential availability impact, which on a DPU means losing the host's networking rather than a single guest. Affects ESXi 8.x and 9.x hosts using AMD-Pensando DPU products.

Who can reach it

A local attacker inside an unprivileged guest VM on an affected ESXi host. No host credentials and no management-network access required; AMD rates attack complexity high.

What to do

Apply the driver/firmware updates listed in AMD bulletin AMD-SB-2001 for the affected ESXi versions. Replacing an ionic driver on ESXi means putting the host into maintenance mode, evacuating or shutting down its VMs, installing the VIB and rebooting - a full drain of the host, which is expensive on a GPU node with pinned, long-running jobs. Check the bulletin for the exact fixed driver and DPU firmware versions for your ESXi build before scheduling the window.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.