GPU VulnDB

Database/Firmware, BMC & network fabric

Ampere AmpereOne AC03 before 3.5.9.3, AC04 before 4.4.5.2, AmpereOne M before 5.4.5.1

CVE-2025-62863Firmware, BMC & network fabricAMP-SB-0007AmpereOne UEFI-MM PCIe driver OOB writecurated

Impact

A malformed SMC from the normal world produces an out-of-bounds write inside the S-EL0 UEFI-MM secure partition. That is code execution in the secure world reached from the OS - the boundary AmpereOne uses to protect runtime firmware services. Once there, the attacker can rewrite firmware state, forge attestation, or persist across a tenant handoff. The bulletin's siblings give a secure-partition-context OOB write (CVE-2025-62864) and an S-EL0 info leak (CVE-2025-62862), so the whole SMC surface should be treated as compromised until patched.

Who can reach it

Host kernel or hypervisor issuing SMC calls on an AmpereOne node. On bare-metal AmpereOne rental this is the tenant. No physical or network access needed.

What to do

Update to the fixed firmware for your part - AC03 3.5.9.3, AC04 4.4.5.2, AmpereOne M 5.4.5.1 - from the board OEM. Flash + reboot + drain per node; because this is in UEFI-MM, it ships as part of the platform firmware bundle and the ODM must integrate Ampere's release before you can install it. Verify the running version after reboot; AmpereOne firmware version strings are per-SKU and easy to get wrong on a mixed fleet.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.