Database/Firmware, BMC & network fabric
Intel processors (bounds check bypass store): Spectre 1.1: speculative stores can overflow a bounds-checked buffer
CVSS 5.6CVE-2018-3693Firmware, BMC & network fabricSpectre 1.1Bounds Check Bypass Storecurated
Impact
Spectre 1.1: speculative stores can overflow a bounds-checked buffer, letting an attacker write speculatively into structures that steer later speculation. Extends Spectre v1 from a read primitive to a write-and-redirect one inside a sandbox.
Who can reach it
Local code execution, particularly inside interpreters and JITs handling untrusted input.
What to do
Software mitigation in compilers, kernels and runtimes rather than microcode. Take kernel and runtime updates; reboot for the kernel component.
References
Related entries
- Intel processors (snoop-assisted L1D sampling): Data can be leaked out of L1D during snoop transactions, crossingCVE-2020-0550 · Intel processors (snoop-assisted L1D sampling)Medium
- Intel processors / SGX (load value injection): The inverse of Meltdown: instead of leaking data out of the enclave, theCVE-2020-0551 · Intel processors / SGX (load value injection)Medium
- AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715): The LFENCE/JMP sequence AMD originallyCVE-2021-26401 · AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715)Medium
- Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-ACVE-2022-23960 · Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-A; also tracked by Ampere as…Medium
- Intel irdma driver (Ethernet Controller RDMA for Linux): Improper access control in the Intel RDMA driver lets anCVE-2023-25775 · Intel irdma driver (Ethernet Controller RDMA for Linux)Medium
- Intel TDX module: An out-of-bounds read in the TDX module reachable by an authenticated user, leaking informationCVE-2024-33607 · Intel TDX moduleMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.