Database/Firmware, BMC & network fabric
AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical): An academic disclosure achieving
Impact
An academic disclosure achieving arbitrary code execution on the AMD Security Processor itself. Code execution in the ASP means control of SEV key management and attestation for every confidential guest on the node. AMD scopes it out as requiring physical access, but shipped defence-in-depth firmware anyway - which is a reasonable signal about how seriously to take it.
Who can reach it
Physical access to the platform.
What to do
AMD shipped **defence-in-depth** PI updates - MilanPI 1.0.0.J and GenoaPI 1.0.0.H (both December 2025) - so there is something to deploy despite the WONTFIX-adjacent framing. Delivered as an OEM SBIOS package with the usual lag and a power cycle. The mitigation state is **tenant-verifiable via Platform Info Bit 5** in the attestation report, which is worth advertising to confidential-computing customers: they can check you applied it rather than taking your word.
References
Related entries
- UEFI Secure Boot (Microsoft 2011 CA/KEK expiry): Not an exploitable flaw but a fleet-wide trust-anchor deadlineNCVD-2026-006-uefi-secure-boot-microsoft-2011 · UEFI Secure Boot (Microsoft 2011 CA/KEK expiry)Unscored
- Community / open-source SONiC (sonic-net): Community SONiC — the open-source NOS that a growing share of cost-optimisedNCVD-2026-013-community-open-source-sonic-soni · Community / open-source SONiC (sonic-net)Unscored
- Rack PDU and UPS management estates as a class (all vendors): PHYSICAL, and the most common real-world findingNCVD-2026-018-rack-pdu-and-ups-management-esta · Rack PDU and UPS management estates as a class (all vendors)Unscored
- Leased colocation facility infrastructure (power, cooling, access control) as a class: Most GPU operators lease spaceNCVD-2026-019-leased-colocation-facility-infra · Leased colocation facility infrastructure (power, cooling, access control) as a classUnscored
- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostNCVD-2026-023-nvme-admin-command-set-firmware · NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the…Unscored
- RAID/HBA controller firmware update path as a classNCVD-2026-025-raid-hba-controller-firmware-upd · RAID/HBA controller firmware update path as a class - Broadcom MegaRAID and LSI 9400/9500/9600 HBAs, Microchip…Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.