Database/Firmware, BMC & network fabric
AMD processors - speculative reordering of loads on shared memory: AMD processors may speculatively reorder load
Impact
AMD processors may speculatively reorder load instructions such that stale data is observed when several processors operate on shared memory. Where that shared memory spans a trust boundary - a shared page between a guest and the host, or between containers - stale reads become a disclosure channel, and worse, code that relies on memory ordering for its own security checks can be made to see the wrong value.
Who can reach it
Local, requires shared memory between attacker and victim and multiple processors operating on it concurrently.
What to do
Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch.
References
Related entries
- AMD SEV firmware - SEV-ES guest attacking an SNP guest: Coarse access-control granularity in SEV firmware lets aCVE-2025-48514 · AMD SEV firmware - SEV-ES guest attacking an SNP guestMedium
- AMD Secure Processor kernel - DRAM mapping into protected areas (AMD-SB-3003): An access-control gap in the ASP kernelCVE-2021-26387 · AMD Secure Processor kernel - DRAM mapping into protected areas (AMD-SB-3003)Low
- Intel SGX SDK (Edger8r code generator): The Edger8r tool generates the trusted/untrusted bridge code for enclavesCVE-2025-32004 · Intel SGX SDK (Edger8r code generator)Low
- Intel SGX DCAP for Windows: Input-validation flaw in the Windows DCAP components allowing local information disclosureCVE-2023-42776 · Intel SGX DCAP for WindowsLow
- AMD processors - speculative inference of control registers despite UMIP: Part of the Transient Scheduler Attacks batchCVE-2024-36348 · AMD processors - speculative inference of control registers despite UMIPLow
- AMD processors - speculative inference of TSC_AUX when reads are disabled: Sibling of the other Transient SchedulerCVE-2024-36349 · AMD processors - speculative inference of TSC_AUX when reads are disabledLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.