- Joined
- Dec 19, 2005
- Messages
- 17,421
“Researchers attack AMD's Infinity Fabric to bypass hardware security protections with 'Fabricked' — flaw lets malicious cloud hosts silently read confidential VM memory and forge attestation reports
Researchers at ETH Zurich disclosed a software-only vulnerability in April that silently undermines AMD SEV-SNP confidential computing protections on AMD's EPYC platforms, giving a malicious cloud host full read and write access to supposedly protected virtual machine memory. The technique, dubbed “Fabricked,” exploits flaws in how the CPU's Infinity Fabric interconnect handles memory routing during boot — and can forge the cryptographic attestation reports tenants rely on to verify their environment hasn't been tampered with.“
Source: https://www.tomshardware.com/pc-com...ntial-vm-memory-and-forge-attestation-reports