Database/Kernel, userspace & hypervisor
AMD CPU (Inception / SRSO): Inception: Speculative Return Stack Overflow
Impact
Inception: Speculative Return Stack Overflow - attacker-controlled speculative disclosure across privilege domains on Zen 1-4
Who can reach it
Any tenant process in a container; tenant VM guest
What to do
Microcode + kernel mitigation (spec_rstack_overflow=) + reboot. Standing perf cost - the safe-RET mitigation is measurable on syscall-heavy workloads
Fleet impact
How widespread
very common - spans Zen 1 through Zen 4, i.e. essentially every AMD host CPU generation in service
Cost to remediate
microcode+reboot **and** a kernel update (SRSO safe-return / IBPB-on-entry); on Zen 1/2 the mitigation additionally requires **disabling SMT**, which permanently cuts logical core count on those nodes
Why it hits the whole fleet
Kernel-memory disclosure via speculative return redirection across the whole AMD lineup; the SMT-disable mitigation is a capacity hit the operator has to absorb fleet-wide, not a one-time reboot.
References
Related entries
- QEMU (net): Triggerable assertion via a race on NIC hot-unplug - guest can abort the host QEMU processCVE-2023-3301 · QEMU (net)Medium
- Xen / Intel CPU (ITS): Indirect Target Selection - speculative execution leak across privilege domains on Intel partsCVE-2024-28956 · Xen / Intel CPU (ITS)Medium
- AMD CPU (TSA-L1): Transient Scheduler Attack - store-to-load forwarding leak across contexts on Zen 3/4CVE-2024-36350 · AMD CPU (TSA-L1)Medium
- AMD CPU (TSA-SQ): Transient Scheduler Attack via the store queue - cross-context information leakCVE-2024-36357 · AMD CPU (TSA-SQ)Medium
- Linux kernel (arch/x86/kvm): Guest-supplied array indices in the host's local-APIC emulation (an IPI destination id andCVE-2025-39823 · Linux kernel (arch/x86/kvm)Medium
- Intel CPU (SRBDS / CrossTalk): Special Register Buffer Data SamplingCVE-2020-0543 · Intel CPU (SRBDS / CrossTalk)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.