Database/Firmware, BMC & network fabric

AMI AptioV UEFI BIOS (SMM): A write-what-where primitive plus an information leak in System Management Mode
Impact
A write-what-where primitive plus an information leak in System Management Mode - the most privileged execution context on an x86 server, above the kernel and invisible to the hypervisor. An attacker who wins here can write anywhere in memory including SMRAM, disable firmware protections, and install a bootkit that persists across OS reinstall and survives every host-level detection you run. Scope is changed, so the compromise reaches beyond the BIOS into the running system. On a shared GPU host this defeats the boundary that VM isolation and confidential-computing attestation both rest on.
Who can reach it
Local, requires high privileges - root or kernel-level code on the host OS. So the precondition is that an attacker already owns the operating system on a node; this is what they use to convert a revocable OS compromise into permanent firmware residency. In a bare-metal GPU rental model, the tenant themselves have that privilege by design.
What to do
BIOS update to AptioV_5.040 or later. That is a firmware flash plus a full host reboot per node, which on a GPU fleet means draining the node - and if it is part of a multi-node training job, draining the whole ring. Rollout is gated on your server vendor picking up the AMI BKC and publishing a rebased BIOS for your specific SKU, which typically lags AMI's advisory by months. There is no config-only mitigation for an SMM bug. If you cannot patch, the compensating control is to stop treating host root as a containable compromise: rebuild affected nodes with a verified BIOS reflash rather than an OS reimage.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.