GPU VulnDB

Database/Firmware, BMC & network fabric

Intel processors: speculative sampling of stale data from microarchitectural buffers (MDS)

CVSS 5.6CVE-2018-12126Firmware, BMC & network fabric+2 more CVEsMSBDSFalloutcurated

Impact

Data left in internal CPU buffers can be read speculatively across privilege, hyperthread, VM and SGX boundaries with no architectural access, so on nodes with SMT enabled and untrusted co-tenants the isolation between tenants does not hold. Intel split the same sampling flaw across 3 ids for the different buffers involved (store buffers, load ports, uncacheable-memory accesses); there is one advisory, one microcode fix and one mitigation state for all of them.

Who can reach it

Local code on the same physical core - with SMT enabled that includes a co-tenant on the sibling thread, which is the configuration most density-optimised fleets run.

What to do

Apply the Intel microcode update for INTEL-SA-00233 together with the OS/hypervisor MDS mitigation, then reboot. Distribution-packaged early-loadable microcode covers this class, so no OEM BIOS release is needed. After reboot, confirm the mitigation from /sys/devices/system/cpu/vulnerabilities/mds rather than from the installed package version, and disable SMT if that file reports SMT vulnerable and the node runs untrusted co-tenants.

Also covers 2 CVEs

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2018-12127CVE-2019-11091

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.