Database/Firmware, BMC & network fabric
Intel processors (return predictor target sharing): Return predictor targets are shared non-transparently
Impact
Return predictor targets are shared non-transparently between contexts, giving an authorised local user an information-disclosure channel. Fixed in the same microcode wave as the 2024 return-predictor advisories.
Who can reach it
Local authorised code.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect.
References
Related entries
- Insyde InsydeH2O BmpDecoderDxe: Crafted BMP logo copies data to a chosen address during DXECVE-2023-40238 · Insyde InsydeH2O BmpDecoderDxeMedium
- shim (verify_buffer_authenticode): Out-of-bounds read on a malformed PE file crashes shim and blocks bootCVE-2023-40549 · shim (verify_buffer_authenticode)Medium
- shim (verify_buffer_sbat): Out-of-bounds read in SBAT verification discloses adjacent boot-time memory to an attackerCVE-2023-40550 · shim (verify_buffer_sbat)Medium
- Linux kernel (drivers/infiniband/sw/rxe): Soft-RoCE queue-pair cleanup drains send and receive work queues that aCVE-2023-53528 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- Linux kernel (drivers/infiniband/sw/rxe): If soft-RoCE queue-pair creation fails partway, the unwind path runs cleanupCVE-2023-54028 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- Linux bnxt_re RoCE driver (chip context memory leak): Memory leak in the Broadcom RoCE driver when doorbell BAR mappingCVE-2024-50172 · Linux bnxt_re RoCE driver (chip context memory leak)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.