Spectre haunts CPUs again: VMSCAPE vulnerability leaks cloud secrets
ID: 45668ace-42ec-54ca-a8e5-e1f77bcc73be
STIX ID: report--45668ace-42ec-54ca-a8e5-e1f77bcc73be
Feed Name: The Register (Security)
VMSCAPE (CVE-2025-40300) is a Spectre v2–style transient-execution vulnerability discovered by ETH Zurich that breaks branch predictor isolation between guest and host, allowing a malicious guest VM on KVM/QEMU to leak host/hypervisor memory (authors report 32 B/s on Zen 4 and key extraction within ~772 s). The flaw affects AMD Zen 1–5 and Intel Coffee Lake CPUs; hardware fixes are impractical, so Linux developers implemented software mitigations (IBPB-before-exit/IBPB-on-VMExit) with varying performance costs (~10% for emulated devices, ~1% on Zen 4), and vendors are coordinating patches and guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
