Database/Firmware, BMC & network fabric
AMD processors - transient execution beyond unconditional direct branches: Some AMD CPUs transiently execute
Impact
Some AMD CPUs transiently execute instructions past an unconditional direct branch - code that should never run, running speculatively and leaving traces in the cache. That gives an attacker speculative gadgets in places the compiler and the kernel's own Spectre auditing assume are unreachable, so hardened code can still leak. The practical outcome is data disclosure across privilege and guest boundaries.
Who can reach it
Local, from an unprivileged process or a guest VM.
What to do
Mitigated by kernel-side changes that insert INT3 speculation barriers after unconditional branches in sensitive paths. Take the distro kernel update and reboot; no firmware step for the kernel mitigation itself. Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch.
References
Related entries
- InsydeH2O: BIOS user and administrator password hashes exposed in runtime-readable UEFI variablesCVE-2021-43613 · Insyde InsydeH2O SysPasswordDxe (BIOS password hashes in runtime UEFI variables)Medium
- Lanner IAC-AST2500A BMC firmware: The attacker rewrites who is permitted to use KVM and virtual media on the BMCCVE-2021-44776 · Lanner IAC-AST2500A BMC firmwareMedium
- AMD SEV / SEV-ES / SEV-SNP - ciphertext observability: SEV encrypts guest memory deterministically per physicalCVE-2021-46744 · AMD SEV / SEV-ES / SEV-SNP - ciphertext observabilityMedium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): The transmit health reporter's dump callback casts itsCVE-2021-46931 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)Medium
- Linux kernel Soft-RoCE completer (rdma_rxe, invalid lkey handling in atomic operations): The local key is the RDMACVE-2021-47076 · Linux kernel Soft-RoCE completer (rdma_rxe, invalid lkey handling in atomic operations)Medium
- Linux kernel RDMA core + mlx5_ib (ib_uverbs_ex_create_flow, flow steering rule creation): The port number a tenantCVE-2021-47265 · Linux kernel RDMA core + mlx5_ib (ib_uverbs_ex_create_flow, flow steering rule creation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.