Database/Firmware, BMC & network fabric
Intel processors (shared resource isolation): Improper isolation of shared processor resources allowing information
Impact
Improper isolation of shared processor resources allowing information disclosure to a local authenticated user. Fixed in the same microcode drop as the associated Atom domain-bypass issue; relevant to any multi-tenant host.
Who can reach it
Local authenticated code on the host.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect.
References
Related entries
- Intel Atom processors (domain-bypass transient execution): A domain-bypass transient execution flaw on Atom partsCVE-2020-24513 · Intel Atom processors (domain-bypass transient execution)Medium
- Intel SGX DCAP (datacenter attestation primitives): An improper conditions check in DCAP lets an unauthenticatedCVE-2020-8766 · Intel SGX DCAP (datacenter attestation primitives)Medium
- Intel Ethernet 800 Series Controller firmware: Out-of-bounds read in 800-series (E810 family) adapter firmwareCVE-2021-0009 · Intel Ethernet 800 Series Controller firmwareMedium
- AMD processors - transient execution beyond unconditional direct branches: Some AMD CPUs transiently executeCVE-2021-26341 · AMD processors - transient execution beyond unconditional direct branchesMedium
- InsydeH2O: BIOS user and administrator password hashes exposed in runtime-readable UEFI variablesCVE-2021-43613 · Insyde InsydeH2O SysPasswordDxe (BIOS password hashes in runtime UEFI variables)Medium
- Lanner IAC-AST2500A BMC firmware: The attacker rewrites who is permitted to use KVM and virtual media on the BMCCVE-2021-44776 · Lanner IAC-AST2500A BMC firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.