GPU VulnDB

Database/Control plane, storage & DevOps

AMD confidential computing - DDR5 memory bus interposition against TEEs: MULTI-TENANT ISOLATION: Compromising trusted

NCVD-2025-006-amd-confidential-computing-ddr5Control plane, storage & DevOpsAMD-SB-3040curated

Impact

MULTI-TENANT ISOLATION: Compromising trusted execution environments by interposing on the DDR5 memory bus. Same family as the BadRAM interposer work and the same conclusion for an operator: SEV-SNP's guarantees are software- and firmware-scoped, and an adversary with hands on the hardware sits outside them.

Who can reach it

Physical access with DDR5 bus interposition hardware.

What to do

**No patch** - physical attacks fall outside the declared SEV-SNP threat model. Mitigation is datacenter physical security, hardware chain of custody, and honest scoping of what confidential computing does and does not promise your tenants.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.