GPU VulnDB

Database/Firmware, BMC & network fabric

AMD PSP chipset driver - permissive device DACL: The PSP chipset driver's discretionary access control list lets

CVE-2021-26333Firmware, BMC & network fabriccurated

Impact

The PSP chipset driver's discretionary access control list lets low-privileged users open a handle to the PSP device. Once open, an unprivileged process can query the driver and read back information it should not have - and, more importantly, it has a handle on the secure processor interface that every other PSP bug then becomes reachable through. Weak device permissions are what turn 'requires privilege' into 'requires a shell'.

Who can reach it

Local, unprivileged - which is the notable part. Worth explicitly checking on any node where you hand semi-trusted workloads local execution.

What to do

Fixed by updating the AMD PSP chipset driver package and reloading it or rebooting. Driver-speed rather than BIOS-speed, so this is one you can actually close quickly. Audit the permissions on your PSP/ccp device node as part of the same pass - a device that unprivileged users can open is a standing invitation.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.