GPU VulnDB

Database/Firmware, BMC & network fabric

AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical): MULTI-TENANT ISOLATION

NCVD-2026-002-amd-sev-firmware-arbitrary-codeFirmware, BMC & network fabricAMD-SB-3033curated

Impact

MULTI-TENANT ISOLATION: An academic disclosure achieving arbitrary code execution on the AMD Security Processor itself. Code execution in the ASP means control of SEV key management and attestation for every confidential guest on the node. AMD scopes it out as requiring physical access, but shipped defence-in-depth firmware anyway - which is a reasonable signal about how seriously to take it.

Who can reach it

Physical access to the platform.

What to do

AMD shipped **defence-in-depth** PI updates - MilanPI 1.0.0.J and GenoaPI 1.0.0.H (both December 2025) - so there is something to deploy despite the WONTFIX-adjacent framing. Delivered as an OEM SBIOS package with the usual lag and a power cycle. The mitigation state is **tenant-verifiable via Platform Info Bit 5** in the attestation report, which is worth advertising to confidential-computing customers: they can check you applied it rather than taking your word.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.