GPU VulnDB

Database/Firmware, BMC & network fabric

AmpereOne firmware: malformed SMC call to UEFI-MM MMCommunicate causes out-of-bounds write in the Secure Partition

CVSS 9.8CVE-2025-62864Firmware, BMC & network fabriccurated

Impact

An incorrectly formed SMC call into the UEFI-MM MMCommunicate service writes out of bounds inside the UEFI-MM Secure Partition context. That partition runs at a higher privilege than the host kernel and owns variable services and other platform state, so a successful write corrupts code or data that the operating system cannot inspect or defend against, and persistence below the OS is plausible. For Arm-based AmpereOne hosts used as head nodes, storage servers or accelerator hosts, this breaks the assumption that re-imaging a node returns it to a known state. Ampere's bulletin AMP-SB-0007 is the authority on exact exposure; the NVD record does not say which privilege level can issue the SMC, and the 9.8 network vector looks broader than an SMC-based local interface would normally allow.

Who can reach it

Issuing a malformed SMC to the UEFI-MM MMCommunicate service, which requires code execution on the host at a privilege level that can make SMC calls - in practice host kernel or firmware-level code. The NVD vector claims AV:N/PR:N; treat that with caution and read AMP-SB-0007 before concluding this is remotely reachable.

What to do

Flash fixed platform firmware: AmpereOne AC03 3.5.9.3 or later, AC04 4.4.5.2 or later, AmpereOne M 5.4.5.1 or later. This is a host firmware update, so each node must be drained and taken out of service for the flash and a power cycle - schedule it as a rolling maintenance window across the affected fleet. There is no OS-level mitigation.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.