Database/Firmware, BMC & network fabric
Intel processors (intra-mode branch target injection): The intra-mode sibling of BHI: branch predictor state is shared
Impact
The intra-mode sibling of BHI: branch predictor state is shared within a privilege level, so one sandboxed context can steer another's speculation without crossing rings. The concern is sandbox escape inside a single process - JIT tenants sharing a runtime.
Who can reach it
Local code inside the same privilege level as the victim, e.g. a sandboxed JIT tenant.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect.
References
Related entries
- AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037): Aliases in the branchCVE-2022-23816 · AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037)Medium
- fwupd's Redfish plugin: Any unprivileged local user on the host can read a working BMC credential out of a config fileCVE-2022-3287 · fwupd's Redfish pluginMedium
- AMD processors - power reporting side channel against SEV VMs: An authenticated attacker uses the platform's powerCVE-2023-20575 · AMD processors - power reporting side channel against SEV VMsMedium
- Intel Ethernet Controller E810 Series firmware: A race condition in E810 firmware lets an authenticated local userCVE-2023-22276 · Intel Ethernet Controller E810 Series firmwareMedium
- Intel E810 Ethernet Controller firmware: Out-of-bounds read in E810 firmware reachable from an adjacentCVE-2023-28376 · Intel E810 Ethernet Controller firmwareMedium
- Intel processors (register file data sampling): RFDS: stale data left in the integer, floating-point and vectorCVE-2023-28746 · Intel processors (register file data sampling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.