USENIX Security2026Top-tier venue
Jailbreaking the AMD Secure Processor: Enabling Live Analysis of SEV-SNP's Undocumented Security Boundaries
Muyan Shen, Hongzhan Ma, Ketong Shang, Ruofei Qu, Yu Qin, Dengguo Feng
Abstract
AMD's Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP) protects virtual machines using its hardware root of trust, the AMD Secure Processor (ASP). However, its security relies on complex, opaque firmware features, such as a dynamic hot-patching mechanism, that create attack surfaces shielded from independent scrutiny. To overcome this "black-box" challenge, we present ASPBreaker, the first practical, fully deterministic jailbreak of the ASP, achieved by exploiting a novel combination of memory aliasing and time-of-check-to-time-of-use (TOCTOU) vulnerability.
Using this jailbreak as a tool for live analysis, we demonstrate how achieving arbitrary code execution on a vulnerable firmware version can be used to subvert the security of a subsequent, fully-patched one. Our analysis revealed critical flaws, enabling two practical attacks against the latest firmware: one that allows an adversary to decrypt the memory of a virtual machine and another that bypasses existing mitigations to forge attestation reports. Our findings, which were responsibly disclosed, demonstrate a fundamental break in the forward-security model of SEV-SNP and highlight the critical need for independent auditing of opaque firmware boundaries.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6f8f1d0a-585e-4a88-9c23-780710cfcb5dCited by top-tier papers1
Ask how each one uses itBuilds on16
- CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side ChannelMengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li et al.USENIX Security 2021 · 130 citations
- A Systematic Look at Ciphertext Side Channels on AMD SEV-SNPMengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth et al.S&P 2022 · 87 citations
- SEVurity: No Security Without Integrity : Breaking Integrity-Free Memory Encryption with Minimal AssumptionsLuca Wilke, Jan Wichelmann, Mathias Morbitzer, Thomas EisenbarthS&P 2020 · 72 citations
- Insecure Until Proven Updated: Analyzing AMD SEV's Remote AttestationRobert Buhren, Christian Werling, Jean-Pierre SeifertCCS 2019 · 60 citations
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi et al.USENIX Security 2024 · 48 citations
Related papers
- STALEUS: Breaking AMD SEV-SNP via Memory IncoherenceBenedict Schlüter, Shweta ShindeUSENIX Security 2026
- One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted VirtualizationRobert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre SeifertCCS 2021
- CounterSEVeillance: Performance-Counter Attacks on AMD SEV-SNPStefan Gast, Hannes Weissteiner, Robin Leander Schröder, Daniel GrussNDSS 2025
- RMPocalypse: How a Catch-22 Breaks AMD SEV-SNPBenedict Schlüter, Shweta ShindeCCS 2025 · 1 citation
- BreakFAST: Confused Deputy Attack on Infinity Fabric to Break AMD SEV-SNPPhilipp Giersfeld, Benedict Schlüter, Shweta ShindeS&P 2026 · 1 citation
