Database/Firmware, BMC & network fabric
AMD processors - transient non-canonical loads and stores using lower 48 address bits: Combined with specific software
Impact
Combined with specific software sequences, AMD CPUs transiently execute non-canonical loads and stores using only the lower 48 address bits - so an access that should fault instead speculatively reads a truncated address. That truncation can land inside another security domain's memory, and the result is observable through the usual cache channels. Data leakage across the boundaries the address canonicality check was supposed to enforce.
Who can reach it
Local, needs the victim to contain a specific software sequence, so exploitability depends on what is running - but on a shared node you do not control what your tenants run.
What to do
Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch. Kernel-side mitigations exist for the known sequences; take the distro kernel update as well as the firmware.
References
Related entries
- Brocade Fabric OS (config and secnotify processes): Running a routine security scan against the SAN switch crashesCVE-2020-15383 · Brocade Fabric OS (config and secnotify processes)High
- GRUB2 (rmmod command): Use-after-free in the rmmod commandCVE-2020-25632 · GRUB2 (rmmod command)High
- GRUB2 (grub_parser_split_cmdline): Stack buffer overflow from variable expansion in the GRUB command lineCVE-2020-27749 · GRUB2 (grub_parser_split_cmdline)High
- AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsing: Insufficient validation when parsing OCACVE-2021-26406 · AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsingHigh
- Arista EOS (VXLAN match rule in IPv4 ACL): If an IPv4 access list contains a VXLAN match rule, that rule and every ruleCVE-2021-28505 · Arista EOS (VXLAN match rule in IPv4 ACL)High
- Arista EOS (TerminAttr / IPsec): TerminAttr leaks IPsec sensitive material in plaintext to authorized usersCVE-2021-28508 · Arista EOS (TerminAttr / IPsec)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.