Database/Kernel, userspace & hypervisor
AMD Zen 1-Zen 5 - branch predictor isolation between guest and userspace hypervisor (AMD-SB-7046): Insufficient
Impact
Insufficient branch-predictor isolation between a guest VM and the **userspace** hypervisor process - QEMU - lets a malicious guest train the predictor and then steer speculation inside the VMM that manages it. The VMM has the guest's memory mapped, so this is a Spectre-class read of confidential guest state from a process the guest can influence. AMD rates it High and, unusually, it spans **Zen 1 through Zen 5** - there is no 'we are on new silicon' escape from this one.
Who can reach it
From inside a guest VM. Tenant-reachable, no host privilege required. Affects every AMD generation currently in datacenter service.
What to do
Fixed in the Linux kernel by issuing a conditional IBPB after every VMexit before returning to userspace. Take the distro kernel update and reboot the host - no firmware, BIOS or microcode step, which makes it one of the cheaper fixes to deploy. **Expect a real performance cost**: the kernel commit itself notes the IBPB duplicates the context-switch IBPB and that workloads switching frequently between hypervisor and userspace absorb the most overhead. On a virtualised GPU fleet with heavy device emulation, benchmark before and after rather than assuming it is free.
References
Related entries
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amd/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeCVE-2025-40310 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amd/amdkfd)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2025-40332 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Xen / x86 CPU: Floating Point Divider State Sampling - transient-execution leak of FP divider state across domainsCVE-2025-54505 · Xen / x86 CPUUnscored
- Xen (Viridian): Incorrect input sanitisation in Viridian (Hyper-V enlightenment) hypercallsCVE-2025-58147 · Xen (Viridian)Unscored
- Linux kernel bpf: BPF_REFCOUNT field was not marked unique in the verifier's field checksCVE-2026-100074 · Linux kernel BPF verifier (bpf_refcount not marked as a unique field)Unscored
- Xen (EPT): Use-after-free of EPT paging structures - HVM guest to host compromiseCVE-2026-23554 · Xen (EPT)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.