GPU VulnDB

Database/Firmware, BMC & network fabric

AMD CPU cache initialization - SEV-SNP guest memory integrity: MULTI-TENANT ISOLATION: Improper initialization of CPU

CVE-2024-36331Firmware, BMC & network fabriccurated

Impact

MULTI-TENANT ISOLATION: Improper initialization of CPU cache memory lets a hypervisor-privileged attacker overwrite SEV-SNP guest memory, costing guest data integrity. Cache-state manipulation is a recurring theme in SEV attacks (the CacheWarp research works the same seam) because the encryption protects DRAM, not what the cache does on the way there.

Who can reach it

Hypervisor-privileged attacker.

What to do

Fixed in AMD SEV firmware / AGESA and reaches you as an OEM SBIOS package - AMD hands AGESA to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before shipping BIOS. **Budget one to six months of OEM lag**, longer on older platforms and sometimes never on end-of-support SKUs. Applying it means draining the host and doing a full power cycle. Because the fix moves the platform's reported SEV-SNP TCB version, you must also pull fresh VCEK certificates from AMD's Key Distribution Service and update any attestation policy your tenants pin - otherwise guests will start failing launch validation the moment the BIOS lands. Some SEV firmware can alternatively be staged from linux-firmware (amd/amd_sev_*.sbin) and committed via the ccp driver at boot, which is faster than waiting on BIOS - check whether your platform supports firmware hot-load before assuming the OEM is the only route.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.