Database/Firmware, BMC & network fabric
AMD SEV-ES / SEV-SNP - transient-execution-amplified power side channel: Graz researchers amplified the power side
Impact
Graz researchers amplified the power side channel with transient execution to extract AES key bytes from inside SEV-ES and SEV-SNP guests. The significance for an operator is the trend line: power telemetry keeps turning out to be a channel that memory encryption does not cover, and each iteration extracts more with less. If you sell confidential computing, the host's power meter is part of your attack surface.
Who can reach it
Requires a malicious hypervisor with access to power telemetry (RAPL) on a host running confidential guests.
What to do
**No CVE and no microcode fix** - AMD's answer is to restrict or disable hypervisor RAPL access. That is a configuration change you can make today at no performance cost: ensure the host's energy interfaces are root-only and are not exposed to any process a tenant can influence, and do not pass power telemetry into guests. No reboot, no firmware. Combine with performance-determinism mode if you are also mitigating Collide+Power, accepting the throughput cost that carries.
References
Related entries
- Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing): Battering RAM: a cheap DRAM interposer that aliasesNCVD-2025-002-intel-sgx-and-amd-sev-snp-dram-i · Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing)Unscored
- AMD SEV-SNP - ciphertext side channels amplified by hypervisor page movement: Two 2025 follow-ups to CipherLeaksNCVD-2025-003-amd-sev-snp-ciphertext-side-chan · AMD SEV-SNP - ciphertext side channels amplified by hypervisor page movementUnscored
- AMD SEV-SNP - RMP entries cached in L1D/L2 leaking physical address bits: Reverse-map table entries cached in L1D andNCVD-2025-004-amd-sev-snp-rmp-entries-cached-i · AMD SEV-SNP - RMP entries cached in L1D/L2 leaking physical address bitsUnscored
- AMD SEV-SNP - DIMM interposer variant of BadRAM (KU Leuven): A memory-bus interposer variant of the BadRAM aliasingNCVD-2025-005-amd-sev-snp-dimm-interposer-vari · AMD SEV-SNP - DIMM interposer variant of BadRAM (KU Leuven)Unscored
- AMD Secure Processor boot ROM - physical attacks bypassing secure boot: Physical attacks that bypass secure boot in theNCVD-2025-007-amd-secure-processor-boot-rom-ph · AMD Secure Processor boot ROM - physical attacks bypassing secure bootUnscored
- Intel SGX / DDR4 memory bus (physical interposer): WireTap: a low-cost passive DDR4 interposer reads the memory bus ofNCVD-2025-012-intel-sgx-ddr4-memory-bus-physic · Intel SGX / DDR4 memory bus (physical interposer)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.