Database/Firmware, BMC & network fabric
AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715): The LFENCE/JMP sequence AMD originally
Impact
The LFENCE/JMP sequence AMD originally recommended as the cheap Spectre-v2 mitigation (mitigation V2-2) turns out not to sufficiently block branch target injection on some AMD CPUs. Anyone who took AMD's early guidance and chose LFENCE/JMP over retpoline because it was faster has been running with a Spectre-v2 mitigation that does not actually hold - a cross-VM and cross-process speculative disclosure channel that people believe is already closed. The dangerous part is the false sense of coverage, not the novelty of the attack.
Who can reach it
Local, cross-privilege and cross-guest speculative execution. Reachable from any tenant workload on affected hardware.
What to do
Switch from LFENCE/JMP to retpoline or hardware IBRS/IBPB. On Linux, verify what is actually active by reading /sys/devices/system/cpu/vulnerabilities/spectre_v2 on your fleet - do not assume, check, because the string tells you exactly which mitigation the kernel selected. Changing it needs a kernel update and/or boot parameter change plus a reboot; on some platforms full IBRS also needs microcode from an SBIOS update. Retpoline and IBRS both cost performance relative to LFENCE/JMP, which is why the weaker option got chosen in the first place.
References
Related entries
- Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-ACVE-2022-23960 · Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-A; also tracked by Ampere as…Medium
- Intel irdma driver (Ethernet Controller RDMA for Linux): Improper access control in the Intel RDMA driver lets anCVE-2023-25775 · Intel irdma driver (Ethernet Controller RDMA for Linux)Medium
- Intel TDX module: An out-of-bounds read in the TDX module reachable by an authenticated user, leaking informationCVE-2024-33607 · Intel TDX moduleMedium
- Intel Atom processors (shared predictor transient execution): Shared microarchitectural predictor state influencesCVE-2024-43420 · Intel Atom processors (shared predictor transient execution)Medium
- Intel processors (indirect branch predictor race): Branch Privilege Injection: a race in how the indirect branchCVE-2024-45332 · Intel processors (indirect branch predictor race)Medium
- Intel Core processors, 10th generation (shared predictor state): Shared predictor state influencing transient executionCVE-2025-20623 · Intel Core processors, 10th generation (shared predictor state)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.