GPU VulnDB

Database/Firmware, BMC & network fabric

AMD SEV-SNP - ciphertext side channels amplified by hypervisor page movement: MULTI-TENANT ISOLATION: Two 2025

NCVD-2025-003-amd-sev-snp-ciphertext-side-chanFirmware, BMC & network fabricRelocate+VoteChosen Plaintext Oracle against SEV-SNPAMD-SB-3021curated

Impact

MULTI-TENANT ISOLATION: Two 2025 follow-ups to CipherLeaks - Toronto's Relocate+Vote and ETH Zurich's chosen-plaintext oracle - both combine ciphertext visibility with the hypervisor's ability to move or swap guest pages. Relocating a page changes which address the deterministic encryption is keyed to, giving the attacker the equivalent of a chosen-plaintext oracle against a confidential VM. AMD publishes this as informational with **no CVE**, which is the point worth noting: your vulnerability scanner will never mention it.

Who can reach it

Malicious hypervisor able to observe guest ciphertext and relocate guest pages.

What to do

**No patch.** The available control is guest policy: SEV-SNP ABI 1.58 and later let a guest forbid hypervisor page move and swap, which removes the amplification. As the operator, support and document that policy bit so tenants can set it; as a tenant-facing claim, be honest that ciphertext visibility on Zen 3 and Zen 4 is architectural. The durable fix is Ciphertext Hiding on Zen 5 (Turin) - a hardware refresh, not a maintenance window.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.