Описание
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
linux | fixed | 4.14.12-1 | package | |
nvidia-graphics-drivers | fixed | 384.111-1 | package | |
nvidia-graphics-drivers | fixed | 384.111-4~deb9u1 | stretch | package |
nvidia-graphics-drivers | fixed | 340.106-1 | jessie | package |
nvidia-graphics-drivers | end-of-life | wheezy | package | |
nvidia-graphics-drivers-legacy-340xx | fixed | 340.106-1 | package | |
nvidia-graphics-drivers-legacy-340xx | fixed | 340.106-1~deb9u1 | stretch | package |
nvidia-graphics-drivers-legacy-304xx | unfixed | package | ||
nvidia-graphics-drivers-legacy-304xx | no-dsa | stretch | package | |
nvidia-graphics-drivers-legacy-304xx | no-dsa | jessie | package | |
linux-grsec | removed | package | ||
xen | fixed | 4.11.1~pre+1.733450b39b-1 | package | |
xen | fixed | 4.8.3+comet2+shim4.10.0+comet3-1+deb9u4 | stretch | package |
xen | ignored | jessie | package |
Примечания
https://meltdownattack.com/
https://xenbits.xen.org/xsa/advisory-254.html
https://googleprojectzero.blogspot.co.uk/2018/01/reading-privileged-memory-with-side.html
http://blog.cyberus-technology.de/posts/2018-01-03-meltdown.html
Paper: https://meltdownattack.com/meltdown.pdf
https://01.org/security/advisories/intel-oss-10003
EPSS
Связанные уязвимости
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
ELSA-2018-4006: Unbreakable Enterprise kernel security update (IMPORTANT)
Уязвимость процессоров Intel и АRM, вызванная ошибкой контроля доступа к памяти при спекулятивном выполнении инструкций процессора, позволяющая нарушителю раскрыть защищаемую информацию
EPSS