Researchers reported a physical attack technique that they say can potentially undermine the integrity guarantees of AMD Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP) on systems using DDR5 memory. According to their report, an adversary who has privileged software access and physical access to the motherboard can insert a t hardware device between the processor and a DDR5 memory module.
AMD has assessed this report and has determined that the described technique relies on a physical attack against the memory bus, which falls outside the scope of the published threat model for SEV-SNP. AMD does not plan to assign a CVE or release mitigations in response to this report. For more information the protections offered by SEV-SNP, please see AMD SEV-SNP: Strengthening VM Isolation with Integrity Protection and More
AMD EPYC™ 4004 Series Processors AMD EPYC™ 4005 and AMD EPYC™ 4005 Embedded Series Processors AMD EPYC™ 8004 and AMD EPYC™ 8004 Embedded Series Processors AMD EPYC™ 9004 and AMD EPYC™ 9004 Embedded Series Processors AMD EPYC™ 9005 and AMD EPYC™ 9005 Embedded Series Processors AMD Instinct™ MI300A Series Processors
AMD thanks the following for reporting and engaging in coordinated vulnerability disclosure:
Jesse De Meulemeester (COSIC, KU Leuven) Patrick Jattke (ETH Zurich) Stefan Gloor (ETH Zurich) Ingrid Verbauwhede (COSIC, KU Leuven) Martin Thompson (Durham University & ZF) David Oswald (Durham University) Kaveh Razavi (ETH Zurich) Jo Van Bulck (DistriNet, KU Leuven)
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
