Database/Firmware, BMC & network fabric
AMD processors - PREFETCH instruction timing and power side channel: Timing and power measurements around the x86
Impact
Timing and power measurements around the x86 PREFETCH instructions leak kernel address space layout on some AMD CPUs. Defeating KASLR is not itself a compromise, but it is the step that converts an unreliable kernel memory-corruption bug - and the amdgpu/amdkfd driver long tail is full of them - into a reliable exploit. Treat it as an exploitability multiplier for everything else in this database.
Who can reach it
Local, unprivileged. Reachable from inside a container.
What to do
Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch. Kernel-side mitigation also exists. Because the value of this bug is chaining, the practical defence is to keep the kernel memory-safety patches current rather than to treat KASLR as a real boundary.
References
Related entries
- AMD processors with SMT - speculative execution across SMT mode switch: With SMT enabled, certain AMD processorsCVE-2022-27672 · AMD processors with SMT - speculative execution across SMT mode switchMedium
- Intel processors (return stack buffer alternate prediction): When the return stack buffer underflows, the processorCVE-2022-28693 · Intel processors (return stack buffer alternate prediction)Medium
- AMD processors - power side channel on cache line data changes: An authenticated attacker who can read CPU powerCVE-2023-20583 · AMD processors - power side channel on cache line data changesMedium
- Linux kernel (drivers/vfio/pci/mlx5): Pages allocated for a device migration buffer are not freed when adding them toCVE-2024-56742 · Linux kernel (drivers/vfio/pci/mlx5)Medium
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareCVE-2021-33082 · Intel / Solidigm SSD, SSD DC and Optane SSD firmware - NVMe Sanitize (Block Erase) leaves prior data recoverableMedium
- AMD SEV firmware - use-after-free allowing a SINGLE_SOCKET guest to activate on the wrong socket (AMD-SB-3023): ACVE-2025-0031 · AMD SEV firmware - use-after-free allowing a SINGLE_SOCKET guest to activate on the wrong socket (AMD-SB-3023)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.