Database/Kernel, userspace & hypervisor
Intel CPU (MDS / ZombieLoad): Microarchitectural Fill Buffer Data Sampling
CVSS 5.9CVE-2018-12130Kernel, userspace & hypervisorcurated
Impact
Microarchitectural Fill Buffer Data Sampling - cross-domain leak from fill buffers, including across SMT siblings
Who can reach it
Any tenant process in a container; tenant VM guest
What to do
Microcode + kernel VERW mitigation + reboot; SMT disable for full protection, with the corresponding throughput loss
References
Related entries
- Linux kernel (drivers/pci): Pci_dev_lock() and the sysfs SR-IOV path took the device lock and the config-space accessCVE-2022-49434 · Linux kernel (drivers/pci)Medium
- OpenSSH (transport): Terrapin: prefix-truncation attack on the SSH Binary Packet ProtocolCVE-2023-48795 · OpenSSH (transport)Medium
- Linux kernel (drivers/pci): The DOE state machine signals the caller's completion before destroying the work_structCVE-2023-54235 · Linux kernel (drivers/pci)Medium
- OpenSSH (sshd): Pre-auth memory/CPU amplification - denial of service against sshdCVE-2025-26466 · OpenSSH (sshd)Medium
- Linux kernel (drivers/pci/endpoint/functions): When BAR allocation fails, the endpoint test function frees the backingCVE-2025-38069 · Linux kernel (drivers/pci/endpoint/functions)Medium
- Linux kernel (drivers/iommu): An unaligned DMA mapping with no aligned middle section calls into the mapper with lengthCVE-2026-53164 · Linux kernel (drivers/iommu)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.