Skip to content

CVE-2025-38560 referencing the wrong CPU attack #59

Description

@dmell

Hello,

The paper linked in CVE-2025-38560's analysis doesn't seem to be the correct one. At Google, we associated this to https://heracles-attack.github.io/ or https://www.usenix.org/conference/usenixsecurity25/presentation/yan-yuqin. Cohere+Reload shouln't have any kernel patch associated with it, as per AMD's bulletin.

Can folks from Oracle have a look?
Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions