Database/Firmware, BMC & network fabric
AMD SEV-SNP - DIMM interposer variant of BadRAM (KU Leuven): A memory-bus interposer variant of the BadRAM aliasing
Impact
A memory-bus interposer variant of the BadRAM aliasing attack against SEV-SNP. AMD's response is **WONTFIX** - the attack is declared outside the SEV-SNP threat model because it requires physical interposition on the memory bus.
Who can reach it
Physical access with a memory-bus interposer.
What to do
**No patch, and none coming** - AMD has scoped it out of the threat model. The operator control is physical: tamper-evident chassis handling, chain of custody, and not making confidential-computing claims that a tenant could reasonably read as covering an adversary with physical access to the DIMM slot. If a customer's threat model includes your own datacenter staff, this is a conversation to have explicitly rather than one to leave to the marketing page.
References
Related entries
- AMD Secure Processor boot ROM - physical attacks bypassing secure boot: Physical attacks that bypass secure boot in theNCVD-2025-007-amd-secure-processor-boot-rom-ph · AMD Secure Processor boot ROM - physical attacks bypassing secure bootUnscored
- Intel SGX / DDR4 memory bus (physical interposer): WireTap: a low-cost passive DDR4 interposer reads the memory bus ofNCVD-2025-012-intel-sgx-ddr4-memory-bus-physic · Intel SGX / DDR4 memory bus (physical interposer)Unscored
- Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing): Battering RAM: a cheap DRAM interposer that aliasesNCVD-2025-013-intel-sgx-and-amd-sev-snp-dram-i · Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing)Unscored
- AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical): An academic disclosure achievingNCVD-2026-002-amd-sev-firmware-arbitrary-code · AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical)Unscored
- UEFI Secure Boot (Microsoft 2011 CA/KEK expiry): Not an exploitable flaw but a fleet-wide trust-anchor deadlineNCVD-2026-006-uefi-secure-boot-microsoft-2011 · UEFI Secure Boot (Microsoft 2011 CA/KEK expiry)Unscored
- Community / open-source SONiC (sonic-net): Community SONiC — the open-source NOS that a growing share of cost-optimisedNCVD-2026-013-community-open-source-sonic-soni · Community / open-source SONiC (sonic-net)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.