CVE-2018-3639
Vulnerability Summary
Timeline
Description
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 46.73%• Percentile: 98%
Techniques & Countermeasures
- CWE-203•Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
Affected Systems
- arm•cortex-a
15 | 57 | 72
- canonical•ubuntu_linux
12.04 | 14.04 | 16.04 | 17.10 | 18.04
- debian•debian_linux
8.0 | 9.0
- intel corporation•multiple
Multiple
- intel•atom_c
c2308 | c3308 | c3338 | c3508 | c3538 | c3558 | c3708 | c3750 | c3758 | c3808 | c3830 | c3850 | c3858 | c3950 | c3955 | c3958
- intel•atom_e
e3805 | e3815 | e3825 | e3826 | e3827 | e3845
- intel•atom_x5-e3930
na
- intel•atom_x5-e3940
na
- intel•atom_x7-e3950
na
- intel•atom_z
z2420 | z2460 | z2480 | z2520 | z2560 | z2580 | z2760 | z3460 | z3480 | z3530 | z3560 | z3570 | z3580 | z3590 | z3735d | z3735e | z3735f | z3735g | z3736f | z3736g | z3740 | z3740d | z3745 | z3745d | z3770 | z3770d | z3775 | z3775d | z3785 | z3795
- intel•celeron_j
j3455 | j4005 | j4105
- intel•celeron_n
n3450
- intel•core_i3
32nm | 45nm
- intel•core_i5
32nm | 45nm
- intel•core_i7
32nm | 45nm
- intel•core_m
32nm | 45nm
- intel•pentium
n4000 | n4100 | n4200
- intel•pentium_j
j4205
- intel•pentium_silver
j5005 | n5000
- intel•xeon_e-1105c
na
- intel•xeon_e3
125c_ | 1220_ | 1275_ | 1505m_v6 | 1515m_v5 | 1535m_v5 | 1535m_v6 | 1545m_v5 | 1558l_v5 | 1565l_v5 | 1575m_v5 | 1578l_v5 | 1585_v5 | 1585l_v5 | 3600 | 5600 | 7500 | e5502 | e5503 | e5504 | e5506 | e5507 | e5520 | e5530 | e5540 | e6510 | e6540 | e6550 | l3403 | l3406 | l3426 | l5506 | l5508_ | l5518_ | l5520 | l5530 | w5580 | w5590 | x3430 | x3440 | x3450 | x3460 | x3470 | x3480 | x5550 | x5560 | x5570
- intel•xeon_e3_1105c_v2
na
- intel•xeon_e3_1125c_v2
na
- intel•xeon_e3_1220_v2
na
- intel•xeon_e3_1220_v3
na
- intel•xeon_e3_1220_v5
na
- intel•xeon_e3_1220_v6
na
- intel•xeon_e3_12201
na
- intel•xeon_e3_12201_v2
na
- intel•xeon_e3_1220l_v3
na
- intel•xeon_e3_1225
na
- intel•xeon_e3_1225_v2
na
- intel•xeon_e3_1225_v3
na
- intel•xeon_e3_1225_v5
na
- intel•xeon_e3_1225_v6
na
- intel•xeon_e3_1226_v3
na
- intel•xeon_e3_1230
na
- intel•xeon_e3_1230_v2
na
- intel•xeon_e3_1230_v3
na
- intel•xeon_e3_1230_v5
na
- intel•xeon_e3_1230_v6
na
- intel•xeon_e3_1230l_v3
na
- intel•xeon_e3_1231_v3
na
- intel•xeon_e3_1235
na
- intel•xeon_e3_1235l_v5
na
- intel•xeon_e3_1240
na
- intel•xeon_e3_1240_v2
na
- intel•xeon_e3_1240_v3
na
- intel•xeon_e3_1240_v5
na
- intel•xeon_e3_1240_v6
na
Showing first 50 affected entries in server-rendered view.
References (147)
- https://access.redhat.com/errata/RHSA-2018:1689
- https://access.redhat.com/errata/RHSA-2018:2162
- https://access.redhat.com/errata/RHSA-2018:1641
- https://usn.ubuntu.com/3680-1/
- https://access.redhat.com/errata/RHSA-2018:1997
- https://access.redhat.com/errata/RHSA-2018:1665
- https://access.redhat.com/errata/RHSA-2018:3407
- https://access.redhat.com/errata/RHSA-2018:2164
- https://access.redhat.com/errata/RHSA-2018:2001
- https://access.redhat.com/errata/RHSA-2018:3423
- https://access.redhat.com/errata/RHSA-2018:2003
- https://usn.ubuntu.com/3654-1/
- https://access.redhat.com/errata/RHSA-2018:1645
- https://access.redhat.com/errata/RHSA-2018:1643
- https://access.redhat.com/errata/RHSA-2018:1652
- https://access.redhat.com/errata/RHSA-2018:3424
- https://access.redhat.com/errata/RHSA-2018:3402
- https://www.us-cert.gov/ncas/alerts/TA18-141A
- https://access.redhat.com/errata/RHSA-2018:1656
- https://access.redhat.com/errata/RHSA-2018:1664
- https://access.redhat.com/errata/RHSA-2018:2258
- https://access.redhat.com/errata/RHSA-2018:1688
- https://access.redhat.com/errata/RHSA-2018:1658
- https://access.redhat.com/errata/RHSA-2018:1657
- https://access.redhat.com/errata/RHSA-2018:2289
- https://access.redhat.com/errata/RHSA-2018:1666
- http://www.securitytracker.com/id/1042004
- https://access.redhat.com/errata/RHSA-2018:1675
- https://access.redhat.com/errata/RHSA-2018:1660
- https://access.redhat.com/errata/RHSA-2018:1965
- https://access.redhat.com/errata/RHSA-2018:1661
- https://access.redhat.com/errata/RHSA-2018:1633
- https://access.redhat.com/errata/RHSA-2018:1636
- https://access.redhat.com/errata/RHSA-2018:1854
- https://access.redhat.com/errata/RHSA-2018:2006
- https://access.redhat.com/errata/RHSA-2018:2250
- http://www.securitytracker.com/id/1040949
- https://access.redhat.com/errata/RHSA-2018:3401
- https://access.redhat.com/errata/RHSA-2018:1737
- https://access.redhat.com/errata/RHSA-2018:1826
- https://usn.ubuntu.com/3651-1/
- https://www.debian.org/security/2018/dsa-4210
- https://www.exploit-db.com/exploits/44695/
- https://access.redhat.com/errata/RHSA-2018:1651
- https://access.redhat.com/errata/RHSA-2018:1638
- https://access.redhat.com/errata/RHSA-2018:1696
- https://access.redhat.com/errata/RHSA-2018:2246
- https://access.redhat.com/errata/RHSA-2018:1644
- https://access.redhat.com/errata/RHSA-2018:1646
- https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html
- https://access.redhat.com/errata/RHSA-2018:1639
- https://access.redhat.com/errata/RHSA-2018:1668
- https://access.redhat.com/errata/RHSA-2018:1637
- https://access.redhat.com/errata/RHSA-2018:2948
- https://www.kb.cert.org/vuls/id/180049
- https://access.redhat.com/errata/RHSA-2018:1686
- https://access.redhat.com/errata/RHSA-2018:2172
- https://access.redhat.com/errata/RHSA-2018:1663
- https://usn.ubuntu.com/3652-1/
- https://access.redhat.com/errata/RHSA-2018:1629
- https://access.redhat.com/errata/RHSA-2018:1655
- https://access.redhat.com/errata/RHSA-2018:1640
- https://access.redhat.com/errata/RHSA-2018:1669
- https://access.redhat.com/errata/RHSA-2018:1676
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180521-cpusidechannel
- https://access.redhat.com/errata/RHSA-2018:3425
- https://access.redhat.com/errata/RHSA-2018:2363
- https://access.redhat.com/errata/RHSA-2018:1632
- https://access.redhat.com/errata/RHSA-2018:1650
- https://access.redhat.com/errata/RHSA-2018:2396
- https://access.redhat.com/errata/RHSA-2018:2364
- https://usn.ubuntu.com/3653-2/
- https://access.redhat.com/errata/RHSA-2018:2216
- https://usn.ubuntu.com/3655-1/
- https://access.redhat.com/errata/RHSA-2018:1649
- https://access.redhat.com/errata/RHSA-2018:2309
- http://www.securityfocus.com/bid/104232
- https://access.redhat.com/errata/RHSA-2018:1653
- https://access.redhat.com/errata/RHSA-2018:2171
- https://access.redhat.com/errata/RHSA-2018:1635
- https://lists.debian.org/debian-lts-announce/2018/09/msg00017.html
- https://access.redhat.com/errata/RHSA-2018:2394
- https://access.redhat.com/errata/RHSA-2018:1710
- https://access.redhat.com/errata/RHSA-2018:1659
- https://access.redhat.com/errata/RHSA-2018:1711
- https://www.debian.org/security/2018/dsa-4273
- https://access.redhat.com/errata/RHSA-2018:1738
- https://access.redhat.com/errata/RHSA-2018:1674
- https://access.redhat.com/errata/RHSA-2018:3396
- https://access.redhat.com/errata/RHSA-2018:1667
- https://usn.ubuntu.com/3654-2/
- https://access.redhat.com/errata/RHSA-2018:1662
- https://access.redhat.com/errata/RHSA-2018:1630
- https://access.redhat.com/errata/RHSA-2018:1647
- https://access.redhat.com/errata/RHSA-2018:1967
- https://usn.ubuntu.com/3655-2/
- https://access.redhat.com/errata/RHSA-2018:3399
- https://access.redhat.com/errata/RHSA-2018:2060
- https://access.redhat.com/errata/RHSA-2018:1690
- https://usn.ubuntu.com/3653-1/
- https://access.redhat.com/errata/RHSA-2018:2161
- https://lists.debian.org/debian-lts-announce/2018/07/msg00038.html
- https://access.redhat.com/errata/RHSA-2018:2328
- https://access.redhat.com/errata/RHSA-2018:1648
- https://access.redhat.com/errata/RHSA-2018:2387
- https://access.redhat.com/errata/RHSA-2019:0148
- https://access.redhat.com/errata/RHSA-2018:1654
- https://usn.ubuntu.com/3679-1/
- https://usn.ubuntu.com/3777-3/
- https://access.redhat.com/errata/RHSA-2018:1642
- https://access.redhat.com/errata/RHSA-2018:3397
- https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html
- https://usn.ubuntu.com/3756-1/
- https://access.redhat.com/errata/RHSA-2018:3398
- https://access.redhat.com/errata/RHSA-2018:3400
- https://access.redhat.com/errata/RHSA-2018:2228
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html
- https://access.redhat.com/errata/RHSA-2019:1046
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00058.html
- https://seclists.org/bugtraq/2019/Jun/36
- http://www.openwall.com/lists/oss-security/2020/06/10/1
- http://www.openwall.com/lists/oss-security/2020/06/10/2
- http://www.openwall.com/lists/oss-security/2020/06/10/5
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdf
- http://support.lenovo.com/us/en/solutions/LEN-22133
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0004
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180012
- https://support.citrix.com/article/CTX235225
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.html
- https://www.synology.com/support/security/Synology_SA_18_23
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
- http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.html
- http://xenbits.xen.org/xsa/advisory-263.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0006
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03850en_us
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1528
- https://security.netapp.com/advisory/ntap-20180521-0001/
- https://nvidia.custhelp.com/app/answers/detail/a_id/4787
- https://support.oracle.com/knowledge/Sun%20Microsystems/2481872_1.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html