Database/Firmware, BMC & network fabric
Intel processors (vector register sampling): Stale values left in vector registers can be sampled by other contexts
CVSS 5.5CVE-2020-0548Firmware, BMC & network fabricVector Register SamplingVRScurated
Impact
Stale values left in vector registers can be sampled by other contexts, leaking data across the process and enclave boundary. Lower yield than the fill-buffer attacks but it targets the vector registers - which is where floating-point tensor data lives on an AI node.
Who can reach it
Local code on the same physical core as the victim.
What to do
Microcode update plus the OS buffer-clearing mitigation, then reboot. Microcode is late-loadable at boot; no OEM BIOS release strictly needed.
References
Related entries
- Intel processors (L1D eviction sampling) / SGX attestation keys: Stale data can be sampled out of L1D fill buffersCVE-2020-0549 · Intel processors (L1D eviction sampling) / SGX attestation keysMedium
- AMD EPYC SEV-ES / SEV-SNP - information disclosure: An information-disclosure flaw in SEV-ES and SEV-SNP on EPYC lets aCVE-2020-12966 · AMD EPYC SEV-ES / SEV-SNP - information disclosureMedium
- Intel processors (fast store forwarding predictor): Improper isolation of a shared microarchitectural resource letsCVE-2020-8698 · Intel processors (fast store forwarding predictor)Medium
- Intel processors (fast store forwarding predictor initialisation): Improper initialisation of a shared predictorCVE-2021-0145 · Intel processors (fast store forwarding predictor initialisation)Medium
- AMD SEV firmware - ASK validation in SEND_START: Insufficient validation of the AMD SEV Signing Key in the SEND_STARTCVE-2021-26320 · AMD SEV firmware - ASK validation in SEND_STARTMedium
- AMD PSP chipset driver - permissive device DACL: The PSP chipset driver's discretionary access control list letsCVE-2021-26333 · AMD PSP chipset driver - permissive device DACLMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.