Database/Firmware, BMC & network fabric
Intel processors (return stack buffer alternate prediction): When the return stack buffer underflows, the processor
Impact
When the return stack buffer underflows, the processor falls back to an alternate predictor that can be influenced by another context, leaking information. Same structural theme as PBRSB: the return predictor is not as well isolated as the ISA implies.
Who can reach it
Local authorised code on the host.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect.
References
Related entries
- AMD processors - power side channel on cache line data changes: An authenticated attacker who can read CPU powerCVE-2023-20583 · AMD processors - power side channel on cache line data changesMedium
- Linux kernel (drivers/vfio/pci/mlx5): Pages allocated for a device migration buffer are not freed when adding them toCVE-2024-56742 · Linux kernel (drivers/vfio/pci/mlx5)Medium
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareCVE-2021-33082 · Intel / Solidigm SSD, SSD DC and Optane SSD firmware - NVMe Sanitize (Block Erase) leaves prior data recoverableMedium
- AMD SEV firmware - use-after-free allowing a SINGLE_SOCKET guest to activate on the wrong socket (AMD-SB-3023): ACVE-2025-0031 · AMD SEV firmware - use-after-free allowing a SINGLE_SOCKET guest to activate on the wrong socket (AMD-SB-3023)Medium
- AMD CPU pipeline configuration - SEV-SNP guest stack pointer corruption: A write-what-where condition in CPU pipelineCVE-2025-29943 · AMD CPU pipeline configuration - SEV-SNP guest stack pointer corruptionMedium
- AMD SEV firmware - ASID range enforcement between SEV-ES and SEV-SNP guests: A malicious hypervisor can launch a SEV-ESCVE-2025-48517 · AMD SEV firmware - ASID range enforcement between SEV-ES and SEV-SNP guestsMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.