Database/Firmware, BMC & network fabric
AMD Secure Processor (Ryzen / Ryzen Pro): MULTI-TENANT ISOLATION: The same class of Secure Processor access-control
Impact
MULTI-TENANT ISOLATION: The same class of Secure Processor access-control failure as RYZENFALL-1, covering three further variants. An administrator-level attacker writes into ASP-protected memory and gains execution in the secure coprocessor, defeating the hardware root of trust the rest of the platform is anchored to.
Who can reach it
Local, administrator-privileged. Requires the attacker to already control the OS on the node.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Client-silicon focused; confirm applicability to your EPYC server SKUs before scheduling.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.