VulnerabilityModified
CVE-2018-3665
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
MEDIUM 5.6EPSS 0.63%
Does this matter?
Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.
Description
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
- CVSS 3.1
- 5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- intel/core i3 · intel/core i5 · intel/core i7 · intel/core m · intel/core m3 · intel/core m5 · intel/core m7 · citrix/xenserver · canonical/ubuntu linux · debian/debian linux · freebsd/freebsd · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux workstation
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/104460Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041124Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041125Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1852Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1944Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2164Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2165Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1170Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1190Third Party Advisory
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlThird Party Advisory
- https://nvidia.custhelp.com/app/answers/detail/a_id/4787Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-18:07.lazyfpu.ascThird Party Advisory
- https://security.netapp.com/advisory/ntap-20181016-0001/Third Party Advisory
- https://security.paloaltonetworks.com/CVE-2018-3665Third Party Advisory
- https://support.citrix.com/article/CTX235745Third Party Advisory
- https://usn.ubuntu.com/3696-1/Third Party Advisory
- https://usn.ubuntu.com/3696-2/Third Party Advisory
- https://usn.ubuntu.com/3698-1/Third Party Advisory
- https://usn.ubuntu.com/3698-2/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4232Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00145.htmlVendor Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.synology.com/support/security/Synology_SA_18_31Third Party Advisory
- http://www.securityfocus.com/bid/104460Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041124Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041125Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1852Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1944Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.