Database/Firmware, BMC & network fabric
Intel processors (branch history injection): BHI / Spectre-BHB: even with eIBRS enabled, the branch history buffer is
Impact
BHI / Spectre-BHB: even with eIBRS enabled, the branch history buffer is shared across privilege levels, so unprivileged code can steer kernel-side speculation and read kernel memory. This is the attack that showed hardware Spectre-v2 mitigations were not the end of the story, and it is directly a container-to-host and guest-to-host read primitive.
Who can reach it
Local unprivileged code - any container or VM on the node.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect. Linux additionally offers unprivileged-eBPF disabling and BHB-clearing sequences; check the spectre_v2 sysfs file after patching to see which mitigation actually engaged.
References
Related entries
- Intel processors (intra-mode branch target injection): The intra-mode sibling of BHI: branch predictor state is sharedCVE-2022-0002 · Intel processors (intra-mode branch target injection)Medium
- AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037): Aliases in the branchCVE-2022-23816 · AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037)Medium
- fwupd's Redfish plugin: Any unprivileged local user on the host can read a working BMC credential out of a config fileCVE-2022-3287 · fwupd's Redfish pluginMedium
- AMD processors - power reporting side channel against SEV VMs: An authenticated attacker uses the platform's powerCVE-2023-20575 · AMD processors - power reporting side channel against SEV VMsMedium
- Intel Ethernet Controller E810 Series firmware: A race condition in E810 firmware lets an authenticated local userCVE-2023-22276 · Intel Ethernet Controller E810 Series firmwareMedium
- Intel E810 Ethernet Controller firmware: Out-of-bounds read in E810 firmware reachable from an adjacentCVE-2023-28376 · Intel E810 Ethernet Controller firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.