Database/Firmware, BMC & network fabric
Intel processors (shared buffers data sampling): Incomplete cleanup of microarchitectural fill buffers lets a local
Impact
Incomplete cleanup of microarchitectural fill buffers lets a local user sample data left behind by other contexts. Part of the MMIO stale-data cluster, whose distinguishing feature is that a guest can pull data across the VM boundary through device MMIO accesses - relevant on any node passing devices through to tenants, which describes every GPU node.
Who can reach it
Local authenticated code, including inside a guest with a passed-through device.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect. The hypervisor half of the mitigation matters here: make sure your VMM's stale-data mitigations are enabled, not just the host microcode. On nodes that host untrusted co-tenants, also disable SMT or enforce core scheduling; that costs real throughput and is a capacity-planning decision, not a free toggle.
References
Related entries
- Intel processors (post-barrier return stack buffer): PBRSB: return predictions made after an IBPB barrier can still useCVE-2022-26373 · Intel processors (post-barrier return stack buffer)Medium
- Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63: A local low-privilege actor gains write accessCVE-2022-43309 · Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63Medium
- Linux kernel (drivers/infiniband/sw/rxe): Any tenant that can open an RDMA verbs device can oops the node. A queue-pairCVE-2022-50127 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- TPM 2.0 reference implementation: Out-of-bounds read in the same routine — disclosure of TPM-resident dataCVE-2023-1018 · TPM 2.0 reference implementationMedium
- Intel processors (return predictor target sharing): Return predictor targets are shared non-transparentlyCVE-2023-38575 · Intel processors (return predictor target sharing)Medium
- Insyde InsydeH2O BmpDecoderDxe: Crafted BMP logo copies data to a chosen address during DXECVE-2023-40238 · Insyde InsydeH2O BmpDecoderDxeMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.