CVE-2018-3639
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 60.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 60.63% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- intel/atom c · intel/atom e · intel/atom x5-e3930 · intel/atom x5-e3940 · intel/atom x7-e3950 · intel/atom z · intel/celeron j · intel/celeron n · intel/core i3 · intel/core i5 · intel/core i7 · intel/core m · intel/pentium · intel/pentium j · intel/pentium silver · intel/xeon e-1105c · intel/xeon e3 · intel/xeon e3 1105c v2 · intel/xeon e3 1125c v2 · intel/xeon e3 1220 v2 · +40 more
- Source
- secure@intel.com
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00058.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.htmlBroken Link
- http://support.lenovo.com/us/en/solutions/LEN-22133Third Party Advisory
- http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/06/10/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/06/10/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/06/10/5Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/104232Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040949Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042004Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-263.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1629Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1630Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1632Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1633Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1635Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1636Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1637Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1638Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1639Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1640Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1641Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1642Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1643Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1644Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1645Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1646Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1647Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1648Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.