CVE-2018-12126

Aliases:ALPINE-CVE-2018-12126DEBIAN-CVE-2018-12126
Advisory lineage Upstream: 0 Downstream: 126
Modified
Published: 30 May 2019, 15:36
Last modified:29 May 2026, 20:09

Vulnerability Summary

Overall Risk (default)
low
23/100
CVSS Score
5.6 MEDIUM
v3.1 (nvd)
EPSS Score
1.51% LOW
2% probability +1.07%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 May 2019, 15:36
Published
Vulnerability first disclosed
29 May 2026, 20:09
Last Modified
Vulnerability information updated

Description

Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVSS Metrics

  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v3.0MEDIUMScore: 5.6CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4.7AV:L/AC:M/Au:N/C:C/I:N/A:N

EPSS Trends

Current EPSS score: 1.51% Percentile: 73%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • alpineintel-ucode

    < 20191112-r0 | < 20191112-r0 | < 20191112-r0 | < 20191112-r0 | < 20191112-r0 | < 20191112-r0 | < 20191112-r0 | < 20191112-r0 | < 20191112-r0 | < 20191112-r0 | < 20191112-r0 | < 20191112-r0

  • alpinexen

    < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.12.0-r2 | < 4.9.4-r1 | < 4.10.3-r1 | < 4.11.1-r2

  • debianintel-microcode

    < 3.20190514.1 | < 3.20190514.1 | < 3.20190514.1 | < 3.20190514.1

  • debianlinux

    < 4.19.37-2 | < 4.19.37-2 | < 4.19.37-2 | < 4.19.37-2

  • debianxen

    < 4.11.1+92-g6c33308a8d-1 | < 4.11.1+92-g6c33308a8d-1 | < 4.11.1+92-g6c33308a8d-1 | < 4.11.1+92-g6c33308a8d-1

  • fedoraprojectfedora

    29

  • intel corporationcentral proccve-2018-12126essing units (cpus)

    A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

  • intelmicroarchitectural_store_buffer_data_sampling_firmware

    na

References (27)