Database/Control plane, storage & DevOps
AMD Zen 1 / Zen+ / Zen 2 - L1D cache way predictor: AMD's L1D way predictor hashes virtual addresses to predict which
Impact
AMD's L1D way predictor hashes virtual addresses to predict which cache way holds a line. Collisions in that hash are observable, giving an attacker a channel to leak metadata about a victim's memory access pattern - the researchers used it to break KASLR, to recover an AES key from a table-based implementation, and to build a covert channel between processes. It works from JavaScript in a browser and across VMs, which is unusually broad reach for a microarchitectural channel.
Who can reach it
Local, unprivileged, co-resident with the victim on the same physical core. Affects Zen 1, Zen+ and Zen 2 (2017-2019 EPYC generations).
What to do
**No CVE was assigned and AMD issued no microcode fix**, taking the position that existing side-channel guidance and secret-independent software already cover it. Treat this as unpatchable on affected silicon. Operator-side controls: do not co-schedule tenants on the same physical core, disable SMT on mixed-tenancy nodes, and prefer newer EPYC generations for workloads where cross-tenant leakage is in your threat model. Nothing here requires a reboot or firmware - it is a scheduling and fleet-composition decision.
References
Related entries
- DDR4 DRAM with in-DRAM TRR; a coupling effect that reaches rows at distance two rather than immediate neighboursNCVD-2021-002-ddr4-dram-with-in-dram-trr-a-cou · DDR4 DRAM with in-DRAM TRR; a coupling effect that reaches rows at distance two rather than immediate neighboursUnscored
- BeeGFS (client-to-metadata/storage service authentication, connAuthFile): Class entry, not a single CVE. Before BeeGFSNCVD-2022-004-beegfs-client-to-metadata-storag · BeeGFS (client-to-metadata/storage service authentication, connAuthFile)Unscored
- BeeGFS (client-to-metadata/storage service authentication, connAuthFile): Class entry, not a single CVE. Before BeeGFSNCVD-2022-005-beegfs-client-to-metadata-storag · BeeGFS (client-to-metadata/storage service authentication, connAuthFile)Unscored
- AMD - Global History Register side channel: A side channel through the branch predictor's Global History RegisterNCVD-2024-001-amd-global-history-register-side · AMD - Global History Register side channelUnscored
- AMD Zen 2, Zen 3 and Zen 4 platforms with DDR4 (7/10 Zen 2 and 6/10 Zen 3 devices flipped) and DDR5 (1/10 devices)NCVD-2024-002-amd-zen-2-zen-3-and-zen-4-platfo · AMD Zen 2, Zen 3 and Zen 4 platforms with DDR4 (7/10 Zen 2 and 6/10 Zen 3 devices flipped) and DDR5 (1/10 devices)Unscored
- AMD Zen 3 / Zen 4 - new exploitation method for SRSO (CVE-2023-20569): Google's security team demonstrated a new way toNCVD-2025-001-amd-zen-3-zen-4-new-exploitation · AMD Zen 3 / Zen 4 - new exploitation method for SRSO (CVE-2023-20569)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.