Database/Firmware, BMC & network fabric
Intel processors (lazy FP state restore): LazyFP: when the OS restores FPU/vector state lazily, one process can
CVSS 5.6CVE-2018-3665Firmware, BMC & network fabricLazyFPcurated
Impact
LazyFP: when the OS restores FPU/vector state lazily, one process can speculatively read another process's floating-point and vector register contents. On an AI node the vector registers hold tensor data and, in crypto-adjacent code, key material.
Who can reach it
Local code on a host whose OS uses lazy FPU state restore.
What to do
Fixed in the OS by switching to eager FPU restore - take the kernel update and reboot. No microcode or BIOS component. Modern kernels already default to eager restore; this matters mostly on frozen legacy images.
References
Related entries
- Intel processors (bounds check bypass store): Spectre 1.1: speculative stores can overflow a bounds-checked bufferCVE-2018-3693 · Intel processors (bounds check bypass store)Medium
- Intel processors (snoop-assisted L1D sampling): Data can be leaked out of L1D during snoop transactions, crossingCVE-2020-0550 · Intel processors (snoop-assisted L1D sampling)Medium
- Intel processors / SGX (load value injection): The inverse of Meltdown: instead of leaking data out of the enclave, theCVE-2020-0551 · Intel processors / SGX (load value injection)Medium
- AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715): The LFENCE/JMP sequence AMD originallyCVE-2021-26401 · AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715)Medium
- Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-ACVE-2022-23960 · Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-A; also tracked by Ampere as…Medium
- Intel irdma driver (Ethernet Controller RDMA for Linux): Improper access control in the Intel RDMA driver lets anCVE-2023-25775 · Intel irdma driver (Ethernet Controller RDMA for Linux)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.