420
VMScore

CVE-2018-3665

Published: 21/06/2018 Updated: 09/06/2021
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.6 | Impact Score: 4 | Exploitability Score: 1.1
VMScore: 420
Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intel core i3 330e

intel core i3 330m

intel core i3 530

intel core i3 540

intel core i3 2120

intel core i3 2120t

intel core i3 2330e

intel core i3 2330m

intel core i3 2370m

intel core i3 2375m

intel core i3 3217u

intel core i3 3217ue

intel core i3 3240t

intel core i3 3245

intel core i3 4012y

intel core i3 4020y

intel core i3 4110e

intel core i3 4110m

intel core i3 4158u

intel core i3 4160

intel core i3 4340

intel core i3 4340te

intel core i3 4350

intel core i3 5010u

intel core i3 5015u

intel core i3 6100h

intel core i3 6100t

intel core i3 6320

intel core i3 8100

intel core i3 380um

intel core i3 390m

intel core i3 2105

intel core i3 2115c

intel core i3 2312m

intel core i3 2328m

intel core i3 2365m

intel core i3 2367m

intel core i3 3130m

intel core i3 3210

intel core i3 3229y

intel core i3 3240

intel core i3 4010u

intel core i3 4010y

intel core i3 4100u

intel core i3 4102e

intel core i3 4150

intel core i3 4150t

intel core i3 4330t

intel core i3 4330te

intel core i3 4370t

intel core i3 5005u

intel core i3 6100

intel core i3 6100e

intel core i3 6167u

intel core i3 6300

intel core i3 6300t

intel core i3 370m

intel core i3 380m

intel core i3 2100

intel core i3 2100t

intel core i3 2102

intel core i3 2310e

intel core i3 2310m

intel core i3 2350m

intel core i3 2357m

intel core i3 3115c

intel core i3 3120m

intel core i3 3120me

intel core i3 3225

intel core i3 3227u

intel core i3 4000m

intel core i3 4005u

intel core i3 4100e

intel core i3 4100m

intel core i3 4130

intel core i3 4130t

intel core i3 4170t

intel core i3 4330

intel core i3 4360t

intel core i3 4370

intel core i3 6006u

intel core i3 6098p

intel core i3 6102e

intel core i3 6157u

intel core i3 330um

intel core i3 350m

intel core i3 550

intel core i3 560

intel core i3 2125

intel core i3 2130

intel core i3 2340ue

intel core i3 2348m

intel core i3 2377m

intel core i3 3110m

intel core i3 3220

intel core i3 3220t

intel core i3 3250

intel core i3 3250t

intel core i3 4025u

intel core i3 4030u

intel core i3 4030y

intel core i3 4112e

intel core i3 4120u

intel core i3 4160t

intel core i3 4170

intel core i3 4350t

intel core i3 4360

intel core i3 5020u

intel core i3 5157u

intel core i3 6100te

intel core i3 6100u

intel core i3 8350k

intel core i5 470um

intel core i5 480m

intel core i5 560um

intel core i5 580m

intel core i5 750s

intel core i5 760

intel core i5 450m

intel core i5 460m

intel core i5 540um

intel core i5 560m

intel core i5 680

intel core i5 750

intel core i5 2390t

intel core i5 2400

intel core i5 2450p

intel core i5 2467m

intel core i5 2537m

intel core i5 2540m

intel core i5 3330

intel core i5 3330s

intel core i5 3360m

intel core i5 3380m

intel core i5 3470t

intel core i5 3475s

intel core i5 3610me

intel core i5 4200h

intel core i5 4210u

intel core i5 4210y

intel core i5 4300u

intel core i5 4300y

intel core i5 4350u

intel core i5 4360u

intel core i5 4430s

intel core i5 4440

intel core i5 4440s

intel core i5 4570t

intel core i5 4570te

intel core i5 4670s

intel core i5 4670t

intel core i5 5257u

intel core i5 5287u

intel core i5 5300u

intel core i5 6260u

intel core i5 6267u

intel core i5 6400t

intel core i5 6402p

intel core i5 6600

intel core i5 6600k

intel core i5 430m

intel core i5 430um

intel core i5 520um

intel core i5 540m

intel core i5 660

intel core i5 661

intel core i5 670

intel core i5 2320

intel core i5 2380p

intel core i5 2435m

intel core i5 2450m

intel core i5 2510e

intel core i5 2515e

intel core i5 2520m

intel core i5 3317u

intel core i5 3320m

intel core i5 3340s

intel core i5 3350p

intel core i5 3470

intel core i5 3470s

intel core i5 3570s

intel core i5 3570t

intel core i5 4210h

intel core i5 4210m

intel core i5 4288u

intel core i5 4300m

intel core i5 4330m

intel core i5 4340m

intel core i5 4422e

intel core i5 4430

intel core i5 4570r

intel core i5 4570s

intel core i5 4670k

intel core i5 4670r

intel core i5 5200u

intel core i5 5250u

intel core i5 5675r

intel core i5 6200u

intel core i5 6360u

intel core i5 6400

intel core i5 6500t

intel core i5 6500te

intel core i5 6585r

intel core i5 8400

intel core i5 8600k

intel core i5 2400s

intel core i5 2405s

intel core i5 2500

intel core i5 2500k

intel core i5 2550k

intel core i5 2557m

intel core i5 3337u

intel core i5 3339y

intel core i5 3427u

intel core i5 3437u

intel core i5 3550

intel core i5 3550s

intel core i5 4200m

intel core i5 4200u

intel core i5 4220y

intel core i5 4250u

intel core i5 4258u

intel core i5 4302y

intel core i5 4308u

intel core i5 4400e

intel core i5 4402e

intel core i5 4460

intel core i5 4460s

intel core i5 4590

intel core i5 4590s

intel core i5 4690

intel core i5 4690k

intel core i5 5350h

intel core i5 5350u

intel core i5 6287u

intel core i5 6300hq

intel core i5 6440eq

intel core i5 6440hq

intel core i5 6600t

intel core i5 6685r

intel core i5 520e

intel core i5 520m

intel core i5 650

intel core i5 655k

intel core i5 2300

intel core i5 2310

intel core i5 2410m

intel core i5 2430m

intel core i5 2500s

intel core i5 2500t

intel core i5 3210m

intel core i5 3230m

intel core i5 3340

intel core i5 3340m

intel core i5 3439y

intel core i5 3450

intel core i5 3450s

intel core i5 3570

intel core i5 3570k

intel core i5 4200y

intel core i5 4202y

intel core i5 4260u

intel core i5 4278u

intel core i5 4310m

intel core i5 4310u

intel core i5 4402ec

intel core i5 4410e

intel core i5 4460t

intel core i5 4570

intel core i5 4590t

intel core i5 4670

intel core i5 4690s

intel core i5 4690t

intel core i5 5575r

intel core i5 5675c

intel core i5 6300u

intel core i5 6350hq

intel core i5 6442eq

intel core i5 6500

intel core i5 8250u

intel core i5 8350u

intel core i7 7y75

intel core i7 640lm

intel core i7 640m

intel core i7 820qm

intel core i7 840qm

intel core i7 920

intel core i7 920xm

intel core i7 970

intel core i7 975

intel core i7 620ue

intel core i7 620um

intel core i7 720qm

intel core i7 740qm

intel core i7 610e

intel core i7 620le

intel core i7 640um

intel core i7 660lm

intel core i7 860

intel core i7 860s

intel core i7 930

intel core i7 940

intel core i7 980

intel core i7 980x

intel core i7 990x

intel core i7 2629m

intel core i7 2630qm

intel core i7 2670qm

intel core i7 2675qm

intel core i7 2820qm

intel core i7 2860qm

intel core i7 2920xm

intel core i7 3555le

intel core i7 3610qe

intel core i7 3632qm

intel core i7 3635qm

intel core i7 3770s

intel core i7 3770t

intel core i7 4578u

intel core i7 4600m

intel core i7 4700hq

intel core i7 4700mq

intel core i7 4720hq

intel core i7 4722hq

intel core i7 4770r

intel core i7 4770s

intel core i7 4790s

intel core i7 4790t

intel core i7 4950hq

intel core i7 4960hq

intel core i7 5700eq

intel core i7 5700hq

intel core i7 7500u

intel core i7 7560u

intel core i7 7567u

intel core i7 7820eq

intel core i7 7820hk

intel core i7 2617m

intel core i7 2620m

intel core i7 2655le

intel core i7 2657m

intel core i7 2720qm

intel core i7 2760qm

intel core i7 3537u

intel core i7 3540m

intel core i7 3615qm

intel core i7 3630qm

intel core i7 3740qm

intel core i7 3770

intel core i7 3770k

intel core i7 4550u

intel core i7 4558u

intel core i7 4700ec

intel core i7 4700eq

intel core i7 4712hq

intel core i7 4712mq

intel core i7 4770hq

intel core i7 4770k

intel core i7 4790

intel core i7 4790k

intel core i7 4900mq

intel core i7 4910mq

intel core i7 5600u

intel core i7 5650u

intel core i7 5850hq

intel core i7 5950hq

intel core i7 7700k

intel core i7 7700t

intel core i7 8700

intel core i7 8700k

intel core i7 875k

intel core i7 880

intel core i7 960

intel core i7 965

intel core i7 2600s

intel core i7 2610ue

intel core i7 2640m

intel core i7 2649m

intel core i7 2710qe

intel core i7 2715qe

intel core i7 3517ue

intel core i7 3520m

intel core i7 3612qm

intel core i7 3615qe

intel core i7 3689y

intel core i7 3720qm

intel core i7 4500u

intel core i7 4510u

intel core i7 4610y

intel core i7 4650u

intel core i7 4702mq

intel core i7 4710hq

intel core i7 4710mq

intel core i7 4765t

intel core i7 4770

intel core i7 4771

intel core i7 4785t

intel core i7 4860hq

intel core i7 4870hq

intel core i7 5550u

intel core i7 5557u

intel core i7 5775r

intel core i7 5850eq

intel core i7 7700

intel core i7 7700hq

intel core i7 8550u

intel core i7 8650u

intel core i7 620lm

intel core i7 620m

intel core i7 660ue

intel core i7 660um

intel core i7 680um

intel core i7 870

intel core i7 870s

intel core i7 940xm

intel core i7 950

intel core i7 2600

intel core i7 2600k

intel core i7 2635qm

intel core i7 2637m

intel core i7 2677m

intel core i7 2700k

intel core i7 2960xm

intel core i7 3517u

intel core i7 3610qm

intel core i7 3612qe

intel core i7 3667u

intel core i7 3687u

intel core i7 3820qm

intel core i7 3840qm

intel core i7 4600u

intel core i7 4610m

intel core i7 4702ec

intel core i7 4702hq

intel core i7 4750hq

intel core i7 4760hq

intel core i7 4770t

intel core i7 4770te

intel core i7 4800mq

intel core i7 4810mq

intel core i7 4850hq

intel core i7 4980hq

intel core i7 5500u

intel core i7 5750hq

intel core i7 5775c

intel core i7 7600u

intel core i7 7660u

intel core i7 7820hq

intel core i7 7920hq

intel core m 5y10

intel core m 5y70

intel core m 5y71

intel core m 5y31

intel core m 5y51

intel core m 5y10a

intel core m 5y10c

intel core m3 6y30

intel core m3 7y30

intel core m3 7y32

intel core m5 6y57

intel core m5 6y54

intel core m7 6y75

citrix xenserver 7.0

citrix xenserver 7.1

citrix xenserver 7.3

citrix xenserver 7.4

citrix xenserver 7.5

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

debian debian linux 8.0

debian debian linux 9.0

freebsd freebsd 11.0

freebsd freebsd 11.1

freebsd freebsd 11.2

redhat enterprise linux 6.0

redhat enterprise linux 7.0

redhat enterprise linux desktop 6.0

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 6.0

redhat enterprise linux workstation 7.0

Vendor Advisories

This update provides mitigations for the lazy FPU vulnerability affecting a range of Intel CPUs, which could result in leaking CPU register states belonging to another vCPU previously scheduled on the same CPU For additional information please refer to xenbitsxenorg/xsa/advisory-267html For the stable distribution (stretch), this proble ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Synopsis Moderate: kernel security update Type/Severity Security Advisory: Moderate Topic An update for kernel is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, whic ...
Synopsis Moderate: kernel-rt security update Type/Severity Security Advisory: Moderate Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score ...
Synopsis Moderate: kernel-rt security, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated kernel-rt packages that fix two security issues and add one enhancement are now available for Red Hat Enterprise MRG 2Red Hat Product Security has rated this update as having a security imp ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Important: kernel-rt security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel-rt is now available for Red Hat Enterprise MRG 2Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVS ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 74 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabili ...
A Floating Point Unit (FPU) state information leakage flaw was found in the way the Linux kernel saved and restored the FPU state during task switch Linux kernels that follow the "Lazy FPU Restore" scheme are vulnerable to the FPU state information leakage issue An unprivileged local attacker could use this flaw to read FPU state bits by conducti ...
Description of Problem An issue has been identified in certain CPUs that may allow code running in a guest VM to read data from another process in the same VM or another VM running on the same host  The data that can be read is limited to specific CPU registers rather than memory or disk storage; however, those registers may contain sensitive ...
CVE-2018-3665 Information Disclosure in WildFire Appliance (WF-500) ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2018-10-30-14 Additional information for APPLE-SA-2018-7-9-4 macOS High Sierra 10136, Security Update 2018-0 ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2018-7-23-1 Additional information for APPLE-SA-2018-7-9-4 macOS High Sierra 10136, Security Update 2018-004 ...

Recent Articles

Hope for Hutchins, Navy sinks contractor, there's another Russian hacking scandal, and more
The Register • Shaun Nichols in San Francisco • 14 Jul 2018

Also, make sure you update your Juniper kit quickly

Roundup This week, when we weren't watching the football and sobbing uncontrollably, we saw security headaches at NPM and Ticketmaster, and a priest in hot water with cybercrime charges. But there's always more in the security world. Here are a few other bits of security news from recent days. The US Senate is asking the Justice Department to look into the possibility that an Islamic extremist hacking group was actually the work of the Russian government. Senators Ron Wyden (D-OR) and Cory Gardn...

Oracle gets busy with Lazy FPU fix, adds more CPU Spectre-protectors
The Register • Richard Chirgwin • 26 Jun 2018

Oracle Linux and VM get their innoculations

Oracle has released fixes for Spectre v3a, Spectre v4, and the “Lazy FPU” vulnerability. The two Spectre patches cover CVE-2018-3640 and CVE-2018-3640. As Oracle's director of security assurance Eric Maurice explained, the patches apply to both Oracle Linux and Oracle VM and the associated Intel microcode. The company was also busy on Friday with fixes for admins with systems that use its Ksplice no-reboot patches. The one everyone was waiting for patches Oracle Linux RHCK 7 against the Inte...

Intel chip flaw: Math unit may spill crypto secrets from apps to malware
The Register • Chris Williams, Editor in Chief • 13 Jun 2018

Nasties on Cores, Xeons may lift computations, mitigations in place or coming

Updated A security flaw within Intel Core and Xeon processors can be potentially exploited to swipe sensitive data from the chips' math processing units. Malware or malicious logged-in users can attempt to leverage this design blunder to steal the inputs and results of computations performed in private by other software. These numbers, held in FPU registers, could potentially be used to discern parts of cryptographic keys being used to secure data in the system. For example, Intel's AES encrypti...