Database/Firmware, BMC & network fabric
AMD processors - speculative inference of TSC_AUX when reads are disabled: Sibling of the other Transient Scheduler
Impact
Sibling of the other Transient Scheduler Attack disclosures. A user process can speculatively infer TSC_AUX even when the platform has disabled that read. TSC_AUX carries the CPU and NUMA node identity, so leaking it tells an attacker exactly where they are running - which is the prerequisite for arranging co-residency with a target tenant and then mounting a cross-core or cross-thread channel against them.
Who can reach it
Local, unprivileged user process on affected AMD parts.
What to do
Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch. Ships with the rest of the July 2025 TSA batch; do not cherry-pick individual CVEs out of it. Benchmark after applying - the TSA mitigations add work on privilege transitions.
References
Related entries
- Hitachi VSP One Block: firmware update path does not validate the image before applying itCVE-2025-0824 · Hitachi Virtual Storage Platform One Block 23/24/26/28 (firmware update validation)Low
- Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledCVE-2026-0995 · Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledLow
- EDK II NetworkPkg (IScsiDxe, Ready-To-Transfer PDU handling): A malicious iSCSI target sends a crafted R2T PDUCVE-2025-2295 · EDK II NetworkPkg (IScsiDxe, Ready-To-Transfer PDU handling)Low
- Dell iDRAC9 / iDRAC10 (memory erase, data remanence): Data survives an iDRAC memory erase and stays readableCVE-2026-70412 · Dell iDRAC9 / iDRAC10 (memory erase, data remanence)Low
- IBM OpenBMC: host can crash the BMC firmware management service or read BMC internal memoryCVE-2026-18857 · IBM OpenBMC (BMC firmware management interface)Low
- AMD SEV guest VMs - TLB flush after VMCB creation sequence: The CPU may fail to flush the TLB after a particularCVE-2021-26342 · AMD SEV guest VMs - TLB flush after VMCB creation sequenceLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.