Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-3639

Опубликовано: 22 мая 2018
Источник: debian
EPSS Средний

Описание

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
intel-microcodefixed3.20180703.1package
linuxfixed4.16.12-1package
linuxfixed4.9.107-1stretchpackage
linuxignoredwheezypackage
xenfixed4.8.3+xsa262+shim4.10.0+comet3-1+deb9u7package
xenignoredjessiepackage

Примечания

  • https://xenbits.xen.org/xsa/advisory-263.html

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1528

  • https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.html

  • The 3.20180703.1 release for intel-microcode was the first batch of updates which targeted

  • most server type CPUs, additional models were supported in the 3.20180807a.1 release

  • Qemu part of the mitigations for the speculative store buffer bypass

  • vulnerabilities on x86 are needed: #908682

  • https://git.qemu.org/?p=qemu.git;a=commit;h=d19d1f965904a533998739698020ff4ee8a103da

  • https://git.qemu.org/?p=qemu.git;a=commit;h=cfeea0c021db6234c154dbc723730e81553924ff

  • https://git.qemu.org/?p=qemu.git;a=commit;h=403503b162ffc33fb64cfefdf7b880acf41772cd

EPSS

Процентиль: 98%
0.46737
Средний

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 7 лет назад

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

CVSS3: 5.6
redhat
около 7 лет назад

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

CVSS3: 5.5
nvd
около 7 лет назад

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

suse-cvrf
почти 7 лет назад

Security update for libvirt

suse-cvrf
около 7 лет назад

Security update for qemu

EPSS

Процентиль: 98%
0.46737
Средний