Database/Firmware, BMC & network fabric
Intel Atom processors (domain-bypass transient execution): A domain-bypass transient execution flaw on Atom parts
Impact
A domain-bypass transient execution flaw on Atom parts leaking information across privilege domains. Matters for edge inference boxes and storage/management appliances built on Atom silicon rather than for Xeon compute nodes - but those appliances often sit inside the trusted network of an AI datacenter.
Who can reach it
Local authenticated code on an affected Atom platform.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect.
References
Related entries
- Intel SGX DCAP (datacenter attestation primitives): An improper conditions check in DCAP lets an unauthenticatedCVE-2020-8766 · Intel SGX DCAP (datacenter attestation primitives)Medium
- Intel Ethernet 800 Series Controller firmware: Out-of-bounds read in 800-series (E810 family) adapter firmwareCVE-2021-0009 · Intel Ethernet 800 Series Controller firmwareMedium
- AMD processors - transient execution beyond unconditional direct branches: Some AMD CPUs transiently executeCVE-2021-26341 · AMD processors - transient execution beyond unconditional direct branchesMedium
- InsydeH2O: BIOS user and administrator password hashes exposed in runtime-readable UEFI variablesCVE-2021-43613 · Insyde InsydeH2O SysPasswordDxe (BIOS password hashes in runtime UEFI variables)Medium
- Lanner IAC-AST2500A BMC firmware: The attacker rewrites who is permitted to use KVM and virtual media on the BMCCVE-2021-44776 · Lanner IAC-AST2500A BMC firmwareMedium
- AMD SEV / SEV-ES / SEV-SNP - ciphertext observability: SEV encrypts guest memory deterministically per physicalCVE-2021-46744 · AMD SEV / SEV-ES / SEV-SNP - ciphertext observabilityMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.