Описание
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| xen | fixed | 4.20.3+127-gc42374a105-1 | package | |
| xen | no-dsa | bookworm | package | |
| xen | end-of-life | bullseye | package |
Примечания
AMD CPU HW issue:
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7053.html
https://roots.ec/blog/fpdss/
Mitigation in src:xen and src:linux:
https://xenbits.xen.org/xsa/advisory-488.html
https://git.kernel.org/linus/e55d98e7756135f32150b9b8f75d580d0d4b2dd3
The Linux kernel has its own CVE CVE-2026-31628 for the lack of mitigation, and
thus only tracked under CVE-2026-31628.
EPSS
Связанные уязвимости
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.
EPSS