USN-5319-1
Vulnerability Summary
Timeline
Description
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, ilinux-lts-xenial, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano Giuffrida discovered that hardware mitigations added by Intel to their processors to address Spectre-BTI were insufficient. A local attacker could potentially use this to expose sensitive information.
Affected Systems
- ubuntu•linux
< 4.4.0-221.254 | < 4.15.0-171.180
- ubuntu•linux-aws
< 4.4.0-1101.106 | < 4.4.0-1137.151 | < 4.15.0-1123.132
- ubuntu•linux-aws-hwe
< 4.15.0-1123.132~16.04.1
- ubuntu•linux-azure
< 4.15.0-1133.146~14.04.1 | < 4.15.0-1133.146~16.04.1
- ubuntu•linux-azure-4.15
< 4.15.0-1133.146
- ubuntu•linux-dell300x
< 4.15.0-1037.42
- ubuntu•linux-gcp
< 4.15.0-1118.132~16.04.1
- ubuntu•linux-gcp-4.15
< 4.15.0-1118.132
- ubuntu•linux-hwe
< 4.15.0-171.180~16.04.1
- ubuntu•linux-kvm
< 4.4.0-1102.111 | < 4.15.0-1109.112
- ubuntu•linux-lts-xenial
< 4.4.0-221.254~14.04.1
- ubuntu•linux-oracle
< 4.15.0-1089.98~16.04.1 | < 4.15.0-1089.98
- ubuntu•linux-raspi2
< 4.15.0-1105.112
- ubuntu•linux-snapdragon
< 4.15.0-1122.131