Database/Firmware, BMC & network fabric
AMD processors - page table walk traces in the last-level cache: The MMU's page table walks during address translation
Impact
The MMU's page table walks during address translation leave traces in the last-level cache, which is shared across cores on an AMD socket. A side-channel attack on the MMU recovers information about a victim's virtual address layout - and since the LLC is shared, this reaches across cores, not just across SMT threads, so core pinning does not help.
Who can reach it
Local, co-resident on the same socket as the victim. Works across cores because the last-level cache is the shared resource.
What to do
**Effectively unpatchable in hardware** - shared last-level cache is a design property, not a bug. Mitigation is architectural: do not co-schedule mutually untrusted tenants on the same socket, and where the threat model demands it, allocate whole nodes rather than slices. On a GPU fleet that maps naturally onto whole-node allocation for sensitive customers, which most operators already offer as a premium tier.
References
Related entries
- Cisco NX-OS (management interface ACL): The ACL you put on the management interface is not enforced, so traffic youCVE-2018-0090 · Cisco NX-OS (management interface ACL)High
- Dell iDRAC7 / iDRAC8 (web server URI parser): Directory traversal in the BMC's own HTTP front end lets an attackerCVE-2018-1211 · Dell iDRAC7 / iDRAC8 (web server URI parser)High
- Arista EOS (BGP UPDATE): Malformed path attribute in a BGP UPDATE from a peer causes denial of serviceCVE-2018-5254 · Arista EOS (BGP UPDATE)High
- Arista EOS (VxLAN agent): Malformed ARP packets crash the VxLAN software forwarding agentCVE-2019-18948 · Arista EOS (VxLAN agent)High
- Lenovo XClarity Administrator (LXCA) - unauthenticated config file access: Unauthenticated access to LXCA configurationCVE-2019-6193 · Lenovo XClarity Administrator (LXCA) - unauthenticated config file accessHigh
- NVIDIA DGX BMC (AMI firmware): A hard-coded RSA-1024 key with weak ciphers in the BMC firmware means the encryptionCVE-2020-11487 · NVIDIA DGX BMC (AMI firmware)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.