Database/Control plane, storage & DevOps
AMD CPU core logic - core hang triggered from an unprivileged VM: Specific code executed from an unprivileged VM can
Impact
Specific code executed from an unprivileged VM can hang an AMD CPU core outright. A guest wedges a physical core on the host, denying it to every other workload scheduled there - and on a GPU node whose CPU cores feed data to accelerators, losing cores starves the GPUs. Availability attack from a tenant against the host, requiring no privilege.
Who can reach it
From inside an unprivileged guest VM. No escalation needed - the guest simply executes a particular sequence.
What to do
Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.