Database/Firmware, BMC & network fabric
Intel processors (indirect branch prediction): Spectre v2: an attacker trains the indirect branch predictor so that a
Impact
Spectre v2: an attacker trains the indirect branch predictor so that a victim context - another process, another VM, or the kernel - speculatively executes an attacker-chosen gadget and leaks its memory through a cache side channel. On a shared GPU host this is the canonical cross-VM and container-to-host read primitive, and it is still the reason retpoline, IBPB and eIBRS exist in every kernel you run.
Who can reach it
Local code execution anywhere on the host - any container, any VM. No privilege needed.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect. On nodes that host untrusted co-tenants, also disable SMT or enforce core scheduling; that costs real throughput and is a capacity-planning decision, not a free toggle.
References
Related entries
- Intel processors (bounds check bypass): Spectre v1: speculative execution past a bounds check lets an attacker readCVE-2017-5753 · Intel processors (bounds check bypass)Medium
- Intel processors (rogue data cache load): Meltdown: unprivileged code reads kernel memory - and on affected partsCVE-2017-5754 · Intel processors (rogue data cache load)Medium
- Intel processors: speculative sampling of stale data from microarchitectural buffers (MDS)CVE-2018-12126 · Intel processors (microarchitectural data sampling)Medium
- Intel processors (L1 terminal fault, OS/SMM): The OS-level variant of L1 terminal fault: a local user can speculativelyCVE-2018-3620 · Intel processors (L1 terminal fault, OS/SMM)Medium
- Intel processors (rogue system register read): Spectre v3a: speculative reads of system registers leak systemCVE-2018-3640 · Intel processors (rogue system register read)Medium
- Intel processors (lazy FP state restore): LazyFP: when the OS restores FPU/vector state lazily, one process canCVE-2018-3665 · Intel processors (lazy FP state restore)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.