Database/Firmware, BMC & network fabric
Linux x86/srso - SRSO mitigation missing for Hygon processors: The kernel's Speculative Return Stack Overflow
Impact
The kernel's Speculative Return Stack Overflow (Inception) mitigation was not applied to Hygon processors, which are AMD Zen derivatives and carry the same defect. Any Hygon node in the fleet therefore ran with the SRSO mitigation silently inactive - a cross-privilege speculative disclosure channel that your vulnerability dashboard reported as mitigated.
Who can reach it
Local, cross-privilege speculative execution on Hygon silicon.
What to do
Fixed in the Linux kernel by extending the SRSO mitigation to Hygon. Distro kernel update plus reboot; no firmware step. Verify afterwards by reading /sys/devices/system/cpu/vulnerabilities/spec_rstack_overflow on Hygon nodes rather than trusting the CPU vendor string to have been handled correctly - this bug existed precisely because it was not.
References
Related entries
- Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migration: KVM fetched source vCPUs from the wrong VMCVE-2023-54296 · Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migrationUnscored
- tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation): tpm2_checkquote does not verify that the structureCVE-2024-29038 · tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation)Unscored
- tpm2-tools (tpm2_checkquote PCR selection handling): tpm2_checkquote does not validate the TPML_PCR_SELECTIONCVE-2024-29039 · tpm2-tools (tpm2_checkquote PCR selection handling)Unscored
- Linux kernel mlxbf_gige (BlueField out-of-band management NIC): NULL function-pointer dereference when the DPU'sCVE-2024-35907 · Linux kernel mlxbf_gige (BlueField out-of-band management NIC)Unscored
- Linux kernel mlx5_core eswitch ingress ACL: The eswitch ingress ACL - the table that enforces per-VF ingress policyCVE-2024-42142 · Linux kernel mlx5_core eswitch ingress ACLUnscored
- Juniper Junos OS (httpd / J-Web on QFX5120, EX, SRX, MX): Crafted HTTP requests to the web management process drive CPUCVE-2025-21601 · Juniper Junos OS (httpd / J-Web on QFX5120, EX, SRX, MX)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.