Database/Firmware, BMC & network fabric
Intel processors (L1 terminal fault, OS/SMM): The OS-level variant of L1 terminal fault: a local user can speculatively
Impact
The OS-level variant of L1 terminal fault: a local user can speculatively read data present in the L1 cache belonging to the kernel or to system-management memory, by faulting on a carefully crafted page-table entry. Sits alongside the hypervisor-level L1TF variant as the reason page-table entry inversion exists in every modern kernel.
Who can reach it
Any local unprivileged code on an affected processor.
What to do
Microcode update plus the kernel's PTE-inversion mitigation, then reboot. Microcode is late-loadable at boot without an OEM BIOS release. Verify with the kernel's l1tf sysfs vulnerability file after reboot rather than assuming.
References
Related entries
- Intel processors (rogue system register read): Spectre v3a: speculative reads of system registers leak systemCVE-2018-3640 · Intel processors (rogue system register read)Medium
- Intel processors (lazy FP state restore): LazyFP: when the OS restores FPU/vector state lazily, one process canCVE-2018-3665 · Intel processors (lazy FP state restore)Medium
- Intel processors (bounds check bypass store): Spectre 1.1: speculative stores can overflow a bounds-checked bufferCVE-2018-3693 · Intel processors (bounds check bypass store)Medium
- Intel processors (snoop-assisted L1D sampling): Data can be leaked out of L1D during snoop transactions, crossingCVE-2020-0550 · Intel processors (snoop-assisted L1D sampling)Medium
- Intel processors / SGX (load value injection): The inverse of Meltdown: instead of leaking data out of the enclave, theCVE-2020-0551 · Intel processors / SGX (load value injection)Medium
- AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715): The LFENCE/JMP sequence AMD originallyCVE-2021-26401 · AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.