GPU VulnDB

Database/Firmware, BMC & network fabric

AMD PSP trusted applications shipped in the AMD Graphics Driver: MULTI-TENANT ISOLATION: Trusted applications bundled

CVE-2020-12929Firmware, BMC & network fabriccurated

Impact

MULTI-TENANT ISOLATION: Trusted applications bundled with the AMD graphics driver and running on the PSP do not validate their parameters, letting a local attacker bypass security restrictions and get arbitrary code execution in the secure processor. Notable because the entry point is the GPU driver stack rather than platform firmware - a GPU-adjacent compromise reaching the platform root of trust.

Who can reach it

Local, via the graphics driver's PSP interface.

What to do

Fixed by updating the AMD graphics driver package (which carries the PSP trusted applications), then reloading the driver or rebooting the node. Unlike the pure-firmware ASP issues this does not wait on an OEM BIOS cycle - it moves at driver-release speed, so it is one of the cheaper ASP-class fixes to deploy.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.