Database/Control plane, storage & DevOps
AMD AGESA bootloader - DDR5 PMIC default configuration: The AGESA bootloader leaves DDR5 memory modules in an insecure
Impact
The AGESA bootloader leaves DDR5 memory modules in an insecure default state with the on-DIMM power management IC interface unprotected. A local user can then reprogram the PMIC and destroy the module - a **permanent**, physical denial of service. This is one of the rare software bugs whose remediation is an RMA: an attacker who runs this across a fleet does not take your nodes offline for a reboot, they take them offline for a parts order.
Who can reach it
Local user privilege on the host. No physical access needed - the PMIC is reachable over the platform's memory-module management interface.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. There is no software undo once a DIMM is bricked. Until the OEM BIOS lands, the mitigation is access control: this needs local execution on the host, so it is a strong argument for not giving semi-trusted workloads a shell on bare metal. Budget for spare DIMMs on any fleet where you cannot patch quickly.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.