Database/Firmware, BMC & network fabric
Intel processors (register file data sampling): RFDS: stale data left in the integer, floating-point and vector
Impact
RFDS: stale data left in the integer, floating-point and vector register files after transient execution can be sampled by a local attacker, crossing the process, VM and enclave boundaries. Vector register files are where model activations and weights live during compute, so on an AI host this leaks the workload's actual data, not just pointers.
Who can reach it
Local authenticated code on an affected processor, including a co-tenant VM or container.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect. The kernel-side mitigation reuses the VERW buffer-clearing path, so a current kernel plus current microcode is the whole story; check the reg_file_data_sampling sysfs entry after reboot.
References
Related entries
- AMI MegaRAC SPx (SPX REST API): Path traversal in the BMC REST API letting a low-privilege user read arbitrary filesCVE-2023-34345 · AMI MegaRAC SPx (SPX REST API)Medium
- Supermicro BMC (IPMI web interface, XSS): Another injection point in the BMC web interface, lower-impact thanCVE-2023-40285 · Supermicro BMC (IPMI web interface, XSS)Medium
- EDK II NetworkPkg (DHCPv6 Advertise, IA_NA/IA_TA option parsing): An integer underflow when parsingCVE-2023-45229 · EDK II NetworkPkg (DHCPv6 Advertise, IA_NA/IA_TA option parsing)Medium
- EDK II NetworkPkg (IPv6 Neighbor Discovery Redirect handling): A truncated ND Redirect message drives an out-of-boundsCVE-2023-45231 · EDK II NetworkPkg (IPv6 Neighbor Discovery Redirect handling)Medium
- Linux kernel (drivers/infiniband/ulp/ipoib): The IPoIB multicast join task drops its lock mid-iteration, letting aCVE-2023-52587 · Linux kernel (drivers/infiniband/ulp/ipoib)Medium
- Linux kernel (drivers/infiniband/core): Rdma_join_multicast accepted queue-pair types other than UD and built theCVE-2023-53525 · Linux kernel (drivers/infiniband/core)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.