Database/Firmware, BMC & network fabric
Intel processors (bounds check bypass): Spectre v1: speculative execution past a bounds check lets an attacker read
Impact
Spectre v1: speculative execution past a bounds check lets an attacker read memory the check was supposed to protect, within the same address space. The practical exposure on an AI node is inside anything that JITs or interprets untrusted input - eBPF, a Python runtime, a model-serving framework's custom-op path.
Who can reach it
Local code execution, including code inside a sandbox or interpreter that is meant to be confined.
What to do
Software mitigation in the kernel and in individual programs (array index masking, speculation barriers) rather than microcode. Take kernel updates, keep runtimes current, and assume any interpreter you expose to untrusted input needs its own hardening. Reboot for the kernel component.
References
Related entries
- Intel processors (rogue data cache load): Meltdown: unprivileged code reads kernel memory - and on affected partsCVE-2017-5754 · Intel processors (rogue data cache load)Medium
- Intel processors: speculative sampling of stale data from microarchitectural buffers (MDS)CVE-2018-12126 · Intel processors (microarchitectural data sampling)Medium
- Intel processors (L1 terminal fault, OS/SMM): The OS-level variant of L1 terminal fault: a local user can speculativelyCVE-2018-3620 · Intel processors (L1 terminal fault, OS/SMM)Medium
- Intel processors (rogue system register read): Spectre v3a: speculative reads of system registers leak systemCVE-2018-3640 · Intel processors (rogue system register read)Medium
- Intel processors (lazy FP state restore): LazyFP: when the OS restores FPU/vector state lazily, one process canCVE-2018-3665 · Intel processors (lazy FP state restore)Medium
- Intel processors (bounds check bypass store): Spectre 1.1: speculative stores can overflow a bounds-checked bufferCVE-2018-3693 · Intel processors (bounds check bypass store)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.