Database/Firmware, BMC & network fabric
Intel Core Ultra processors (branch prediction unit initialisation): Part of the Training Solo family: incorrect
Impact
Part of the Training Solo family: incorrect initialisation of the branch prediction unit lets an attacker self-train a predictor within the victim's own domain, so the leak works without the cross-domain training that existing mitigations assume. That is the significance - it sidesteps domain-isolation mitigations rather than defeating them head-on, and it reopens guest-to-host and user-to-kernel leakage on parts believed fixed.
Who can reach it
Local unprivileged code on an affected processor.
What to do
Mitigated by an Intel microcode update plus OS/hypervisor changes. Microcode for this class is normally shipped by your distribution as an early-loadable image, so you can deploy it with a package update and a reboot without waiting for an OEM BIOS release - that distinction is the difference between a week and a quarter. Verify after reboot by reading /sys/devices/system/cpu/vulnerabilities/ rather than assuming the package took effect. Training Solo also needs kernel-side changes for the eBPF and indirect-branch paths; take both.
References
Related entries
- Arista EOS: stale 802.1X ACL entry survives re-auth and is applied to a new supplicantCVE-2026-75944 · Arista EOS AclAgent (802.1X supplicant ACL state)Medium
- Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Kernel memory disclosureCVE-2011-1044 · Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cqMedium
- Linux kernel SRP target drivers/infiniband/ulp/srpt/ib_srpt.c: An SRP initiator that issues an ABORT_TASK against anCVE-2016-6327 · Linux kernel SRP target drivers/infiniband/ulp/srpt/ib_srpt.cMedium
- AMD Ryzen with AGESA microcode - FMA3 instruction sequence hang: A long series of FMA3 instructions hangs the systemCVE-2017-7262 · AMD Ryzen with AGESA microcode - FMA3 instruction sequence hangMedium
- Intel processors (speculative store bypass): Spectre v4: a load speculatively executes before an older storeCVE-2018-3639 · Intel processors (speculative store bypass)Medium
- Intel SGX Platform Software for Linux (AESM daemon): A local attacker can disable the AESM daemonCVE-2018-3689 · Intel SGX Platform Software for Linux (AESM daemon)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.