Database/Firmware, BMC & network fabric
Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms): MULTI-TENANT ISOLATION: A backdoor in the Promontory
Impact
MULTI-TENANT ISOLATION: A backdoor in the Promontory chipset firmware. The chipset sits on the DMA path for USB, SATA and PCIe, so code running there can read and write host memory independently of the CPU and outside the reach of anything the OS enforces. Included as the canonical example of the risk class rather than as an EPYC issue: third-party chipset silicon in your server has its own firmware, its own DMA capability, and usually no attestation story at all.
Who can reach it
Local, requires the ability to load chipset firmware. Ryzen/Ryzen Pro client platforms rather than EPYC servers.
What to do
Fixed by a chipset firmware update from the OEM, delivered in a BIOS package - drain plus power cycle. Verify applicability before spending a window: this is client-platform silicon and almost certainly not in your EPYC server fleet. The transferable lesson for a datacenter operator is to ask which non-AMD firmware images your server actually loads at boot and who signs them.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.