Database/Firmware, BMC & network fabric
Intel processors (indirect branch predictor race): Branch Privilege Injection: a race in how the indirect branch
Impact
Branch Privilege Injection: a race in how the indirect branch predictor associates predictions with privilege level lets unprivileged code get its predictions applied in kernel context, reading kernel memory even on parts with hardware Spectre-v2 mitigations. The researchers demonstrated reading /etc/shadow on a fully patched machine - it defeats the mitigations operators had been told were sufficient.
Who can reach it
Local unprivileged code on the node - any container or VM.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect. Confirm the specific microcode revision Intel names for your stepping; this one is not fully closed by kernel changes alone.
References
Related entries
- Intel Core processors, 10th generation (shared predictor state): Shared predictor state influencing transient executionCVE-2025-20623 · Intel Core processors, 10th generation (shared predictor state)Medium
- Intel Core Ultra processors (branch prediction unit initialisation): Part of the Training Solo family: incorrectCVE-2025-24495 · Intel Core Ultra processors (branch prediction unit initialisation)Medium
- Arista EOS: stale 802.1X ACL entry survives re-auth and is applied to a new supplicantCVE-2026-75944 · Arista EOS AclAgent (802.1X supplicant ACL state)Medium
- Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Kernel memory disclosureCVE-2011-1044 · Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cqMedium
- Linux kernel SRP target drivers/infiniband/ulp/srpt/ib_srpt.c: An SRP initiator that issues an ABORT_TASK against anCVE-2016-6327 · Linux kernel SRP target drivers/infiniband/ulp/srpt/ib_srpt.cMedium
- AMD Ryzen with AGESA microcode - FMA3 instruction sequence hang: A long series of FMA3 instructions hangs the systemCVE-2017-7262 · AMD Ryzen with AGESA microcode - FMA3 instruction sequence hangMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.