Database/Firmware, BMC & network fabric
Intel processors (fast store forwarding predictor): Improper isolation of a shared microarchitectural resource lets
Impact
Improper isolation of a shared microarchitectural resource lets a local authenticated user infer data from another context. Part of the steady drip of shared-predictor leaks that each cost another microcode revision and another small performance tax.
Who can reach it
Local authenticated code on the host.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect.
References
Related entries
- Intel processors (fast store forwarding predictor initialisation): Improper initialisation of a shared predictorCVE-2021-0145 · Intel processors (fast store forwarding predictor initialisation)Medium
- AMD SEV firmware - ASK validation in SEND_START: Insufficient validation of the AMD SEV Signing Key in the SEND_STARTCVE-2021-26320 · AMD SEV firmware - ASK validation in SEND_STARTMedium
- AMD PSP chipset driver - permissive device DACL: The PSP chipset driver's discretionary access control list letsCVE-2021-26333 · AMD PSP chipset driver - permissive device DACLMedium
- AMD SEV-SNP migration agent (report ID assignment): An imported SEV-SNP guest is not assigned a fresh report ID, so theCVE-2021-26349 · AMD SEV-SNP migration agent (report ID assignment)Medium
- AMD Secure Processor TEE - memory cleanup between trusted applications: The ASP's trusted execution environment failsCVE-2021-26393 · AMD Secure Processor TEE - memory cleanup between trusted applicationsMedium
- Arm Trusted Firmware-M: Non-secure world can halt the system, overwrite secure data, or leak secure data via the NSPECVE-2021-27562 · Arm Trusted Firmware-MMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.