USN-3756-1
Dashboard / Vulnerabilities / USN-3756-1
USN-3756-1
Summary: intel-microcode vulnerabilities
Details: It was discovered that memory present in the L1 data cache of an Intel CPU core may be exposed to a malicious process that is executing on the CPU core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local attacker in a guest virtual machine could use this to expose sensitive information (memory from other guests or the host OS). (CVE-2018-3646) Jann Horn and Ken Johnson discovered that microprocessors utilizing speculative execution of a memory read may allow unauthorized memory reads via a sidechannel attack. This flaw is known as Spectre Variant 4. A local attacker could use this to expose sensitive information, including kernel memory. (CVE-2018-3639) Zdenek Sojka, Rudolf Marek, Alex Zuepke, and Innokentiy Sennovskiy discovered that microprocessors that perform speculative reads of system registers may allow unauthorized disclosure of system parameters via a sidechannel attack. This vulnerability is also known as Rogue System Register Read (RSRE). An attacker could use this to expose sensitive information. (CVE-2018-3640)
References: https://ubuntu.com/security/notices/USN-3756-1, https://ubuntu.com/security/CVE-2018-3639, https://ubuntu.com/security/CVE-2018-3640, https://ubuntu.com/security/CVE-2018-3646
Affected packages
Package
Name: intel-microcode
Purl: pkg:deb/ubuntu/intel-microcode?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
