Database/Kernel, userspace & hypervisor
Intel CPU (Native BHI): Native Branch History Injection - unprivileged user leaks kernel memory despite eIBRS
CVSS 4.7CVE-2024-2201Kernel, userspace & hypervisorcurated
Impact
Native Branch History Injection - unprivileged user leaks kernel memory despite eIBRS; also XSA-456 for Xen
Who can reach it
Any tenant process in a container; tenant VM guest
What to do
Kernel mitigation (BHI_DIS_S or software sequence) + reboot; standing perf cost. Affects Intel Xeon hosts under GPU nodes
References
Related entries
- Linux kernel (drivers/vfio/pci): A failed interrupt-context allocation while enabling INTx leaks the IRQ name string.CVE-2024-38632 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/iommu): Removing a device from the per-IOMMU page-fault queue responds to outstanding faults butCVE-2025-21770 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/pci/controller): The Intel VMD driver guarded config-space access with a lock type that becomes aCVE-2025-23161 · Linux kernel (drivers/pci/controller)Medium
- Linux kernel (ksmbd): Use-after-free in ksmbd session logoff (found by an LLM-assisted audit)CVE-2025-37899 · Linux kernel (ksmbd)Medium
- Linux kernel (drivers/pci/controller): The Hyper-V PCI front-end frees its PCI domain number twice on a probe failureCVE-2026-43097 · Linux kernel (drivers/pci/controller)Medium
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.