CVE-2017-5926
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
Published:Feb 27, 2017
Last Modified:Apr 20, 2025
EPS:Feb 27, 2017
EPSS Score:0.00383
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Allwinner
Product
A64
Allwinner
A64
Vendor
Amd
Product
Athlon Ii 640 X4
Amd
Athlon Ii 640 X4
Vendor
Amd
Product
E-350
Amd
E-350
Vendor
Amd
Product
Fx-8120 8-core
Amd
Fx-8120 8-core
Vendor
Amd
Product
Fx-8320 8-core
Amd
Fx-8320 8-core
Vendor
Amd
Product
Fx-8350 8-core
Amd
Fx-8350 8-core
Vendor
Amd
Product
Phenom 9550 4-core
Amd
Phenom 9550 4-core
Vendor
Intel
Product
Atom C2750
Intel
Atom C2750
Vendor
Intel
Product
Celeron N2840
Intel
Celeron N2840
Vendor
Intel
Product
Core I5 M480
Intel
Core I5 M480
Vendor
Intel
Product
Core I7-2620qm
Intel
Core I7-2620qm
Vendor
Intel
Product
Core I7-3632qm
Intel
Core I7-3632qm
Vendor
Intel
Product
Core I7-4500u
Intel
Core I7-4500u
Vendor
Intel
Product
Core I7-6700k
Intel
Core I7-6700k
Vendor
Intel
Product
Core I7 920
Intel
Core I7 920
Vendor
Intel
Product
Xeon E3-1240 V5
Intel
Xeon E3-1240 V5
Vendor
Intel
Product
Xeon E5-2658 V2
Intel
Xeon E5-2658 V2
Vendor
Nvidia
Product
Tegra K1 Cd570m-a1
Nvidia
Tegra K1 Cd570m-a1
Vendor
Nvidia
Product
Tegra K1 Cd580m-a1
Nvidia
Tegra K1 Cd580m-a1
Vendor
Samsung
Product
Exynos 5800
Samsung
Exynos 5800
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
