Database/Kernel, userspace & hypervisor
Intel CPU (L1TF / Foreshadow-NG): L1 Terminal Fault: a guest reads any data present in the L1 data cache, including
CVSS 5.6CVE-2018-3646Kernel, userspace & hypervisorcurated
Impact
L1 Terminal Fault: a guest reads any data present in the L1 data cache, including other guests' and the hypervisor's memory
Who can reach it
Tenant VM guest
What to do
Microcode + hypervisor L1D-flush mitigation + reboot; full mitigation requires core scheduling or disabling SMT, which costs roughly half the CPU throughput on a hyperthreaded host
References
Related entries
- Intel x86-64 CPUs (Ivy Bridge onward); Windows and Linux kernel entry paths: The kernel's syscall/interrupt entry pathCVE-2019-1125 · Intel x86-64 CPUs (Ivy Bridge onward); Windows and Linux kernel entry pathsMedium
- AMD CPU (Branch Type Confusion): Non-Retbleed branch type confusion - speculative cross-domain leakCVE-2022-23825 · AMD CPU (Branch Type Confusion)Medium
- AMD CPU (Retbleed): Retbleed: arbitrary speculative code execution via return instructionsCVE-2022-29900 · AMD CPU (Retbleed)Medium
- Intel CPU (Retbleed): Retbleed on Intel - speculative execution of return instructions leaks across privilege boundariesCVE-2022-29901 · Intel CPU (Retbleed)Medium
- AMD CPU (Inception / SRSO): Inception: Speculative Return Stack OverflowCVE-2023-20569 · AMD CPU (Inception / SRSO)Medium
- QEMU (net): Triggerable assertion via a race on NIC hot-unplug - guest can abort the host QEMU processCVE-2023-3301 · QEMU (net)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.