Database/Firmware, BMC & network fabric
Intel processors (L1D eviction sampling) / SGX attestation keys: Stale data can be sampled out of L1D fill buffers
Impact
Stale data can be sampled out of L1D fill buffers during cache-line eviction, leaking across privilege and enclave boundaries. The consequence operators care about is the SGAxe result built on it: recovery of the machine's SGX attestation keys, which lets an attacker produce quotes that pass Intel's attestation service for a machine whose enclaves are entirely under their control. Once that happens, remote attestation stops proving anything about that platform.
Who can reach it
Local code on the same core as the victim; with SMT enabled, a sibling-thread co-tenant.
What to do
Microcode update, which is late-loadable at boot without an OEM BIOS release, plus a TCB recovery and re-attestation. Also disable SMT or enforce core scheduling on nodes serving untrusted tenants. Any attestation key material provisioned before the microcode update must be treated as compromised - the fix does not revoke it for you.
References
Related entries
- AMD EPYC SEV-ES / SEV-SNP - information disclosure: An information-disclosure flaw in SEV-ES and SEV-SNP on EPYC lets aCVE-2020-12966 · AMD EPYC SEV-ES / SEV-SNP - information disclosureMedium
- Intel processors (fast store forwarding predictor): Improper isolation of a shared microarchitectural resource letsCVE-2020-8698 · Intel processors (fast store forwarding predictor)Medium
- Intel processors (fast store forwarding predictor initialisation): Improper initialisation of a shared predictorCVE-2021-0145 · Intel processors (fast store forwarding predictor initialisation)Medium
- AMD SEV firmware - ASK validation in SEND_START: Insufficient validation of the AMD SEV Signing Key in the SEND_STARTCVE-2021-26320 · AMD SEV firmware - ASK validation in SEND_STARTMedium
- AMD PSP chipset driver - permissive device DACL: The PSP chipset driver's discretionary access control list letsCVE-2021-26333 · AMD PSP chipset driver - permissive device DACLMedium
- AMD SEV-SNP migration agent (report ID assignment): An imported SEV-SNP guest is not assigned a fresh report ID, so theCVE-2021-26349 · AMD SEV-SNP migration agent (report ID assignment)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.