Database/Firmware, BMC & network fabric
Intel processors (post-barrier return stack buffer): PBRSB: return predictions made after an IBPB barrier can still use
Impact
PBRSB: return predictions made after an IBPB barrier can still use pre-barrier state, so the barrier that hypervisors rely on to separate guests does not fully separate them. The specific worry is a guest reading host memory on a machine where the operator believed IBPB closed that door.
Who can reach it
Local code in a guest or unprivileged context on an affected host.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect. The mitigation also requires a hypervisor/kernel change that stuffs the RSB after VM exit - patch both, and confirm through the spectre_v2 sysfs entry.
References
Related entries
- Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63: A local low-privilege actor gains write accessCVE-2022-43309 · Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63Medium
- Linux kernel (drivers/infiniband/sw/rxe): Any tenant that can open an RDMA verbs device can oops the node. A queue-pairCVE-2022-50127 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- TPM 2.0 reference implementation: Out-of-bounds read in the same routine — disclosure of TPM-resident dataCVE-2023-1018 · TPM 2.0 reference implementationMedium
- Intel processors (return predictor target sharing): Return predictor targets are shared non-transparentlyCVE-2023-38575 · Intel processors (return predictor target sharing)Medium
- Insyde InsydeH2O BmpDecoderDxe: Crafted BMP logo copies data to a chosen address during DXECVE-2023-40238 · Insyde InsydeH2O BmpDecoderDxeMedium
- shim (verify_buffer_authenticode): Out-of-bounds read on a malformed PE file crashes shim and blocks bootCVE-2023-40549 · shim (verify_buffer_authenticode)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.