GPU VulnDB

Database/Firmware, BMC & network fabric

AMD SEV-SNP firmware, guest teardown / UMC key seed handling: TENANT HANDOFF FAILURE

CVE-2023-31355Firmware, BMC & network fabricdecommissioned guest memory disclosureUMC seed reusecurated

Impact

TENANT HANDOFF FAILURE. A malicious hypervisor can overwrite a guest's UMC seed such that memory belonging to an already-decommissioned confidential guest becomes readable. In a rented-GPU business the slot a customer just released is immediately resold; this says the previous tenant's plaintext - checkpoints, weights, prompts, keys still resident in DRAM - can be recovered after their VM is gone. It breaks the one property you cannot buy back with an apology, and it does so on a path your own automation exercises thousands of times a day.

Who can reach it

Malicious or compromised hypervisor / host root, acting after a confidential guest terminates. No access to the victim tenant needed at all - only control of the host they used to be on.

What to do

Same package as CVE-2024-21980 (AMD-SB-3011): hot-loadable SEV firmware 1.37.14 hex (Milan) / 1.37.24 hex (Genoa) with no reboot, or Platform Initialization firmware MilanPI 1.0.0.D / GenoaPI 1.0.0.C via OEM BIOS with a reboot. Prioritize this one over the rest of the batch. Until it is fixed, do not treat guest teardown as a memory-sanitization boundary - force an explicit scrub or a full host reboot between confidential tenants. The fix bumps TCB[SNP], so re-baseline attestation policies.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.