
Bulletin ID: AMP-SB-0008
Problem Statement and Impact
A vulnerability in Ampere® Altra® and Altra® Max processors may permit the use of stale Stage 1 and/or Stage 2 translation table entries under certain conditions.
Mitigation requires Trusted Firmware-A and Hafnium firmware patches distributed by Ampere along with operating system patches.
Arm has submitted patches to the Linux Kernel and Trusted Firmware-A to mitigate this issue.Arm has submitted patches to the Linux Kernel and Trusted Firmware-A to mitigate this issue.
Arm reported this security issue to Ampere Computing.
Severity
High: Where local access to the system requires authentication
CVSS score: 8.8
[CVSS (version 3.1) 8.8/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H]
Critical: Where the system permits local untrusted code execution
CVSS score: 9.3
[CVSS (version 3.1) 9.3/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H]
Fixed in
Ampere Altra Family SRP 2.10j and later
Recommendations
Update firmware to SRP 2.10j or later.
Update operating systems/hypervisor.