Database/Firmware, BMC & network fabric
AMD SEV-SNP - ciphertext side channels amplified by hypervisor page movement: Two 2025 follow-ups to CipherLeaks
Impact
Two 2025 follow-ups to CipherLeaks - Toronto's Relocate+Vote and ETH Zurich's chosen-plaintext oracle - both combine ciphertext visibility with the hypervisor's ability to move or swap guest pages. Relocating a page changes which address the deterministic encryption is keyed to, giving the attacker the equivalent of a chosen-plaintext oracle against a confidential VM. AMD publishes this as informational with **no CVE**, which is the point worth noting: your vulnerability scanner will never mention it.
Who can reach it
Malicious hypervisor able to observe guest ciphertext and relocate guest pages.
What to do
**No patch.** The available control is guest policy: SEV-SNP ABI 1.58 and later let a guest forbid hypervisor page move and swap, which removes the amplification. As the operator, support and document that policy bit so tenants can set it; as a tenant-facing claim, be honest that ciphertext visibility on Zen 3 and Zen 4 is architectural. The durable fix is Ciphertext Hiding on Zen 5 (Turin) - a hardware refresh, not a maintenance window.
References
Related entries
- AMD SEV-SNP - RMP entries cached in L1D/L2 leaking physical address bits: Reverse-map table entries cached in L1D andNCVD-2025-004-amd-sev-snp-rmp-entries-cached-i · AMD SEV-SNP - RMP entries cached in L1D/L2 leaking physical address bitsUnscored
- AMD SEV-SNP - DIMM interposer variant of BadRAM (KU Leuven): A memory-bus interposer variant of the BadRAM aliasingNCVD-2025-005-amd-sev-snp-dimm-interposer-vari · AMD SEV-SNP - DIMM interposer variant of BadRAM (KU Leuven)Unscored
- AMD Secure Processor boot ROM - physical attacks bypassing secure boot: Physical attacks that bypass secure boot in theNCVD-2025-007-amd-secure-processor-boot-rom-ph · AMD Secure Processor boot ROM - physical attacks bypassing secure bootUnscored
- Intel SGX / DDR4 memory bus (physical interposer): WireTap: a low-cost passive DDR4 interposer reads the memory bus ofNCVD-2025-012-intel-sgx-ddr4-memory-bus-physic · Intel SGX / DDR4 memory bus (physical interposer)Unscored
- Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing): Battering RAM: a cheap DRAM interposer that aliasesNCVD-2025-013-intel-sgx-and-amd-sev-snp-dram-i · Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing)Unscored
- AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical): An academic disclosure achievingNCVD-2026-002-amd-sev-firmware-arbitrary-code · AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.