Database/Firmware, BMC & network fabric
AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): MULTI-TENANT ISOLATION: The SEV
Impact
MULTI-TENANT ISOLATION: The SEV implementation in PSP firmware used a broken elliptic-curve parameter check, so an attacker with host privileges can run an invalid-curve attack against the platform Diffie-Hellman exchange and recover the SEV endorsement key. With that key the host can decrypt a guest's launch secret and read the encrypted VM's memory outright. If you sold confidential computing on top of SEV on affected firmware, the guarantee was not there.
Who can reach it
Local, requires hypervisor/host administrator privilege - which is exactly the party SEV is supposed to defend the guest against. No guest cooperation needed.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Because this sits inside the SEV-SNP trust boundary, the update also moves the platform's reported TCB version: after patching you must refresh VCEK certificates from AMD's KDS and update whatever attestation policy your tenants (or your own confidential-VM control plane) pin against, or every guest launch will start failing validation. Fixed in PSP/SEV firmware 0.17 build 22 and later. Any guest launched or attested on older firmware should be treated as having had no confidentiality guarantee - rotate the secrets those guests held rather than just patching forward.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.