Database/Firmware, BMC & network fabric
Intel processors: speculative sampling of stale data from microarchitectural buffers (MDS)
Impact
Data left in internal CPU buffers can be read speculatively across privilege, hyperthread, VM and SGX boundaries with no architectural access, so on nodes with SMT enabled and untrusted co-tenants the isolation between tenants does not hold. Intel split the same sampling flaw across 3 ids for the different buffers involved (store buffers, load ports, uncacheable-memory accesses); there is one advisory, one microcode fix and one mitigation state for all of them.
Who can reach it
Local code on the same physical core - with SMT enabled that includes a co-tenant on the sibling thread, which is the configuration most density-optimised fleets run.
What to do
Apply the Intel microcode update for INTEL-SA-00233 together with the OS/hypervisor MDS mitigation, then reboot. Distribution-packaged early-loadable microcode covers this class, so no OEM BIOS release is needed. After reboot, confirm the mitigation from /sys/devices/system/cpu/vulnerabilities/mds rather than from the installed package version, and disable SMT if that file reports SMT vulnerable and the node runs untrusted co-tenants.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- Intel processors (L1 terminal fault, OS/SMM): The OS-level variant of L1 terminal fault: a local user can speculativelyCVE-2018-3620 · Intel processors (L1 terminal fault, OS/SMM)Medium
- Intel processors (rogue system register read): Spectre v3a: speculative reads of system registers leak systemCVE-2018-3640 · Intel processors (rogue system register read)Medium
- Intel processors (lazy FP state restore): LazyFP: when the OS restores FPU/vector state lazily, one process canCVE-2018-3665 · Intel processors (lazy FP state restore)Medium
- Intel processors (bounds check bypass store): Spectre 1.1: speculative stores can overflow a bounds-checked bufferCVE-2018-3693 · Intel processors (bounds check bypass store)Medium
- Intel processors (snoop-assisted L1D sampling): Data can be leaked out of L1D during snoop transactions, crossingCVE-2020-0550 · Intel processors (snoop-assisted L1D sampling)Medium
- Intel processors / SGX (load value injection): The inverse of Meltdown: instead of leaking data out of the enclave, theCVE-2020-0551 · Intel processors / SGX (load value injection)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.