Understanding Benign SEV-SNP Log Alerts on ESX 9.1 Hosts
search cancel

Understanding Benign SEV-SNP Log Alerts on ESX 9.1 Hosts

book

Article ID: 443049

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

On vSphere 9.1 ESX hosts where SEV-SNP is enabled in the system BIOS, specific warning and failure messages may be recorded in the vmkernel logs during the host boot sequence. These messages are benign and do not impair base product functionality or virtualization stability:

  • Command GET_ID (0xc) failed: INVALID_LENGTH (0x4) (Buffer too small to complete the operation)

  • SEV firmware upgrade needed for IOMMU buffer check

  • SEV: DeviceCmdInterruptWait:540: Command response timeout (<REDACTED_COUNT> so far)

Environment

vSphere ESX 9.1 running on AMD hardware with Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) enabled in the BIOS

Cause

The initialization sequence of the AMD SEV firmware under ESX 9.1 triggers standard operational timeouts and length mismatches during routine registration boundaries. The internal IOMMU buffer verification checks proactively flag older platform firmware on Zen 3 and Zen 4 microarchitectures.

Resolution

No workaround or administrative action is required as these alerts do not indicate an operational failure or structural vulnerability:

  1. Disregard standard behavioral timeouts: The GET_ID failure and the DeviceCmdInterruptWait command response timeout messages are cosmetic events encountered during early boot device probing and can be safely ignored.

  2. Evaluate microarchitecture firmware alignment: The alert SEV firmware upgrade needed for IOMMU buffer check can be safely disregarded if the system is not utilizing AMD Zen 3 or Zen 4 processors. For systems built on Zen 3 or Zen 4 platforms, ensure that the server's AMD platform firmware/AGESA microcode is updated to the latest vendor-approved baseline to align the IOMMU verification checks.

Additional Information

Broadcom Engineering are aware of this issue and it will be resolved in a future release.