CVE-2018-3639

Public on 2018-05-22
Modified on 2018-09-15
Description

An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of Load & Store instructions (a commonly used performance optimization). It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory read from address to which a recent memory write has occurred may see an older value and subsequently cause an update into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to read privileged memory by conducting targeted cache side-channel attacks.

Severity
Important
See what this means
CVSS v3 Base Score
5.6
See breakdown

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 1 java-1.7.0-openjdk 2018-06-08 18:32 ALAS-2018-1037
Amazon Linux 2 - Core java-1.7.0-openjdk 2018-06-08 18:05 ALAS2-2018-1037
Amazon Linux 1 java-1.8.0-openjdk 2018-06-08 18:34 ALAS-2018-1039
Amazon Linux 2 - Core java-1.8.0-openjdk 2018-06-08 18:10 ALAS2-2018-1039
Amazon Linux 1 kernel 2018-06-08 18:33 ALAS-2018-1038
Amazon Linux 2 - Core kernel 2018-06-08 18:08 ALAS2-2018-1038
Amazon Linux 2 - Core libvirt 2018-06-07 23:33 ALAS2-2018-1033
Amazon Linux 2 - Core libvirt 2018-07-24 16:05 ALAS2-2018-1049
Amazon Linux 1 qemu-kvm 2018-06-08 18:29 ALAS-2018-1034
Amazon Linux 2 - Core qemu-kvm 2018-06-07 23:41 ALAS2-2018-1034

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.6 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
NVD CVSSv2 2.1 AV:L/AC:L/Au:N/C:P/I:N/A:N
NVD CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N