GPU VulnDB

Database/Firmware, BMC & network fabric

Intel processors (post-barrier return stack buffer): MULTI-TENANT ISOLATION: PBRSB: return predictions made

CVE-2022-26373Firmware, BMC & network fabricPBRSBPost-barrier Return Stack Buffercurated

Impact

MULTI-TENANT ISOLATION: PBRSB: return predictions made after an IBPB barrier can still use pre-barrier state, so the barrier that hypervisors rely on to separate guests does not fully separate them. The specific worry is a guest reading host memory on a machine where the operator believed IBPB closed that door.

Who can reach it

Local code in a guest or unprivileged context on an affected host.

What to do

Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect. The mitigation also requires a hypervisor/kernel change that stuffs the RSB after VM exit - patch both, and confirm through the spectre_v2 sysfs entry.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.