GPU VulnDB

Database/Control plane, storage & DevOps

AMD TEE / ASP bootloader syscall input validation: Insufficient validation of syscall inputs in the AMD trusted

CVE-2021-46759Control plane, storage & DevOpscurated

Impact

Insufficient validation of syscall inputs in the AMD trusted execution environment lets an attacker who controls a user application running under the ASP bootloader read back ASP bootloader memory - disclosing firmware internals and, more usefully to an attacker, the layout and secrets needed to build a reliable exploit against the secure processor.

Who can reach it

Local plus physical access, and control of a Uapp running under the bootloader. High bar; realistic for an attacker with hands on the hardware (supply chain, colocation insider, returned hardware).

What to do

Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Physical-access requirement means datacenter physical controls and tamper-evident handling are a genuine compensating control here.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.