GPU VulnDB

Database/Firmware, BMC & network fabric

Intel processors (rogue system register read): Spectre v3a: speculative reads of system registers leak system

CVE-2018-3640Firmware, BMC & network fabricSpectre v3aRSRERogue System Register Readcurated

Impact

Spectre v3a: speculative reads of system registers leak system parameters - MSR contents and similar - to unprivileged local code. On its own it exposes configuration rather than data, but that configuration is what an attacker needs to aim the more serious attacks.

Who can reach it

Local unprivileged code.

What to do

Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.