Database/Firmware, BMC & network fabric
AMD SEV-SNP - RMP entries cached in L1D/L2 leaking physical address bits: Reverse-map table entries cached in L1D and
Impact
Reverse-map table entries cached in L1D and L2 leak up to six physical address bits to an **unprivileged** process. AMD and the researchers agree there is no immediate impact, and six bits is not a compromise on its own - but physical address bits are exactly the primitive that makes Rowhammer, cache-eviction-set construction and DMA targeting practical, so it is a building block for other people's attacks rather than an attack itself.
Who can reach it
Local, unprivileged - notably lower than the rest of the RMP family, which mostly needs hypervisor privilege.
What to do
**No fix planned.** Nothing to install and nothing to reboot for. Treat it as a standing reminder that side-channel primitives accumulate: it lowers the cost of the next attack against your SNP hosts without ever appearing in a patch queue. Track AMD-SB-3036 in case AMD's assessment changes.
References
Related entries
- AMD SEV-SNP - DIMM interposer variant of BadRAM (KU Leuven): A memory-bus interposer variant of the BadRAM aliasingNCVD-2025-005-amd-sev-snp-dimm-interposer-vari · AMD SEV-SNP - DIMM interposer variant of BadRAM (KU Leuven)Unscored
- AMD Secure Processor boot ROM - physical attacks bypassing secure boot: Physical attacks that bypass secure boot in theNCVD-2025-007-amd-secure-processor-boot-rom-ph · AMD Secure Processor boot ROM - physical attacks bypassing secure bootUnscored
- Intel SGX / DDR4 memory bus (physical interposer): WireTap: a low-cost passive DDR4 interposer reads the memory bus ofNCVD-2025-012-intel-sgx-ddr4-memory-bus-physic · Intel SGX / DDR4 memory bus (physical interposer)Unscored
- Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing): Battering RAM: a cheap DRAM interposer that aliasesNCVD-2025-013-intel-sgx-and-amd-sev-snp-dram-i · Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing)Unscored
- AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical): An academic disclosure achievingNCVD-2026-002-amd-sev-firmware-arbitrary-code · AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical)Unscored
- UEFI Secure Boot (Microsoft 2011 CA/KEK expiry): Not an exploitable flaw but a fleet-wide trust-anchor deadlineNCVD-2026-006-uefi-secure-boot-microsoft-2011 · UEFI Secure Boot (Microsoft 2011 CA/KEK expiry)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.