Database/Kernel, userspace & hypervisor
AMD CPU (TSA-SQ): Transient Scheduler Attack via the store queue - cross-context information leak
CVSS 5.6CVE-2024-36357Kernel, userspace & hypervisorcurated
Impact
Transient Scheduler Attack via the store queue - cross-context information leak
Who can reach it
Any tenant process in a container; tenant VM guest
What to do
Microcode + kernel mitigation + reboot; standing perf cost; consider disabling SMT for isolation-sensitive tenants
References
Related entries
- Linux kernel (arch/x86/kvm): Guest-supplied array indices in the host's local-APIC emulation (an IPI destination id andCVE-2025-39823 · Linux kernel (arch/x86/kvm)Medium
- Intel CPU (SRBDS / CrossTalk): Special Register Buffer Data SamplingCVE-2020-0543 · Intel CPU (SRBDS / CrossTalk)Medium
- Xen - x86 PV guest denial of service via SYSENTER: SYSENTER leaves state sanitisation to software, and on AMD hardwareCVE-2020-25596 · Xen - x86 PV guest denial of service via SYSENTERMedium
- Xen on x86 - speculative vulnerabilities with bare 32-bit PV guests: Bare (non-shim) 32-bit PV guests run in ring 1, anCVE-2021-28689 · Xen on x86 - speculative vulnerabilities with bare 32-bit PV guestsMedium
- Linux kernel (drivers/iommu/amd): On AMD hosts, switching a device's IOMMU group between a DMA domain and an identityCVE-2021-47140 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2021-47410 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.