Ampere Computing Logo
Contact Sales
Ampere Computing Logo
Hero Image

Root Complex OS Re-Enable

Bulletin ID: AMP-SB-0006
CVE-2022-46892

Who is Impacted

Systems that use OS to disable root port.

Potential Impact

Depending on platform configuration, reenabling root ports may provide unintended access.

Severity:

Low Severity

CVSS Score: 3.6

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

Problem Statement and Impact

A Root complex is typically disabled during boot via the BIOS. However, the OS can overwrite the DSDT ACPI table to reinitialize the Root Complex. Reported by Oracle and discovered by internal Oracle security researcher Hugo Magalhaes.

Fixed in

SRP 2.10c

Affected Products

Ampere® Altra® and Ampere® Altra®Max

Recommendations

Update SRP to 2.10c

Created At : February 14th 2023, 8:51:10 pm
Last Updated At : August 7th 2023, 4:20:19 pm
Ampere Logo

Ampere Computing LLC

4655 Great America Parkway Suite 601

Santa Clara, CA 95054

image
image
image
image
image
 |  |  | 
© 2024 Ampere Computing LLC. All rights reserved. Ampere, Altra and the A and Ampere logos are registered trademarks or trademarks of Ampere Computing.
This site runs on Ampere Processors.