CVE-2017-5715
published 2018-01-04CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker…
PriorityP262medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EXPLOIT
EPSS
74.04%
99.4th percentile
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Affected
939 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | macos_high_sierra_10.13.2_supplemental_update | — | — |
| apple | safari | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | amd64-microcode | < amd64-microcode 3.20180515.1 (bookworm) | amd64-microcode 3.20180515.1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | intel-microcode | < amd64-microcode 3.20180515.1 (bookworm) | amd64-microcode 3.20180515.1 (bookworm) |
| debian | linux | < linux 5.16.12-1 (bookworm) | linux 5.16.12-1 (bookworm) |
| debian | linux | < amd64-microcode 3.20180515.1 (bookworm) | amd64-microcode 3.20180515.1 (bookworm) |
| debian | nvidia-graphics-drivers | < amd64-microcode 3.20180515.1 (bookworm) | amd64-microcode 3.20180515.1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < amd64-microcode 3.20180515.1 (bookworm) | amd64-microcode 3.20180515.1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- ·As of early 2018, there was no known weaponized exploit in the wild for CVE-2017-5715; observed samples were PoC-derived and unconfirmed as functional exploits. ↗
- ·Intel's initial Broadwell and Haswell microcode patches for CVE-2017-5715 were pulled due to causing unexpected reboots and potential data loss/corruption; deploying those versions may destabilize systems. ↗
- ·Virtual scanner appliances can still be indirectly affected by CVE-2017-5715 if the vulnerability is exploitable at the hypervisor level; hypervisor patching is required in addition to guest OS patching. ↗
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_cisco5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM APE1808 Product Family
cisa_ics·2023-09-14
Siemens RUGGEDCOM APE1808 Product Family
ICS Advisory
##
Siemens RUGGEDCOM APE1808 Product Family
Release DateSeptember 14, 2023
Alert CodeICSA-23-257-04
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low Attack Complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM APE1808 Product Family
- Vulnerabilities: Exposure of Sensitive Information to an Unauthorized Actor, Buffer Underflow, Classic Buffer Overflow, Time-of-check Time-of-use Race Condition, Out-of-bounds Read, Im
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
Red Hat
hw: cpu: AMD: IBPB and Return Address Predictor Interactions
vendor_redhat·2022-07-12·CVSS 5.6
CVE-2022-23824 [MEDIUM] CWE-1037 hw: cpu: AMD: IBPB and Return Address Predictor Interactions
hw: cpu: AMD: IBPB and Return Address Predictor Interactions
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
A flaw was found in hw. The AMD CPUs can be attacked similar to the previously known Spectre Variant 2 (CVE-2017-5715). This issue affects AMD CPUs where the OS relies on IBPB to flush the return address predictor. As a result, an unprivileged attacker could use this flaw to cross the syscall and guest/host boundaries and read privileged memory by conducting targeted cache side-channel attacks.
Mitigation: Please see the vulnerability response article for the full list of updates available and a detailed discussion of this issue, which compares the existing mitigation for CVE-2022-23816
Red Hat
hw: cpu: LFENCE/JMP Mitigation Update for CVE-2017-5715
vendor_redhat·2022-03-08·CVSS 5.6
CVE-2021-26401 [MEDIUM] hw: cpu: LFENCE/JMP Mitigation Update for CVE-2017-5715
hw: cpu: LFENCE/JMP Mitigation Update for CVE-2017-5715
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
A flaw was found in hw. The speculative execution window of AMD LFENCE/JMP mitigation (MITIGATION V2-2) may be large enough to be exploited on AMD CPUs.
Mitigation: AMD recommends mitigation that uses generic retpoline.
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not affected
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2021-06-09·CVSS 5.6
CVE-2020-24512 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel processors may not properly invalidate
cache entries used by Intel Virtualization Technology for Directed I/O
(VT-d). This may allow a local user to perform a privilege escalation
attack. (CVE-2020-24489)
Joseph Nuzman discovered that some Intel processors may not properly apply
EIBRS mitigations (originally developed for CVE-2017-5715) and hence may
allow unauthorized memory reads via sidechannel attacks. A local attacker
could use this to expose sensitive information, including kernel
memory. (CVE-2020-24511)
Travis Downs discovered that some Intel processors did not properly flush
cache-lines for trivial-data values. This may allow an unauthorized
Red Hat
hw: improper isolation of shared resources in some Intel Processors
vendor_redhat·2021-06-08·CVSS 5.6
CVE-2020-24511 [MEDIUM] CWE-200 hw: improper isolation of shared resources in some Intel Processors
hw: improper isolation of shared resources in some Intel Processors
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Microcode misconfiguration in some Intel processors may cause EIBRS mitigation (CVE-2017-5715) to be incomplete. As a consequence, this issue may allow an authenticated user to potentially enable information disclosure via local access.
Debian
CVE-2021-26401: linux - LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some...
vendor_debian·2021·CVSS 5.6
CVE-2021-26401 [MEDIUM] CVE-2021-26401: linux - LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some...
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
Scope: local
bookworm: resolved (fixed in 5.16.12-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.12-1)
sid: resolved (fixed in 5.16.12-1)
trixie: resolved (fixed in 5.16.12-1)
BSD
FreeBSD-SA-19:26.mcu: Intel CPU Microcode Update
bsd_advisories·2019-11-12·CVSS 5.6
CVE-2017-5715 [MEDIUM] FreeBSD-SA-19:26.mcu: Intel CPU Microcode Update
FreeBSD-SA-19:26.mcu Security Advisory
The FreeBSD Project
Topic: Intel CPU Microcode Update
Category: 3rd party
Module: Intel CPU microcode
Announced: 2019-11-12
Credits: Intel
Affects: All supported versions of FreeBSD running on certain
Intel CPUs.
CVE Name: CVE-2019-11135, CVE-2019-11139, CVE-2018-12126,
CVE-2018-12127, CVE-2018-12130, CVE-2018-11091,
CVE-2017-5715
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
- From time to time Intel releases new CPU microcode to address functional
issues and security vulnerabilities. Such a release is also known as a
Micro Code Update (MCU), and is a component of a broader Intel Platform
Update (IPU). FreeBSD
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2018-10-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3777-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
%LTS. This update provides the corresponding updates for the
Linux kernel for Azure Cloud systems.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive
Ubuntu
AMD Microcode regression
vendor_ubuntu·2018-07-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] AMD Microcode regression
Title: AMD Microcode regression
Summary: The system could be made to expose sensitive information.
USN-3690-1 provided updated microcode for AMD processors to address
CVE-2017-5715 (aka Spectre). Unfortunately, the update caused some
systems to fail to boot. This update reverts the update for Ubuntu
14.04 LTS.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory.
This update provides the microcode updates for AMD 17H family
processors required for the corresponding Linux kernel updates.
Instructions:
Ubuntu
AMD Microcode update
vendor_ubuntu·2018-06-20
CVE-2017-5715 AMD Microcode update
Title: AMD Microcode update
Summary: The system could be made to expose sensitive information.
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory.
This update provides the microcode updates for AMD 17H family
processors required for the corresponding Linux kernel updates.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Palo Alto
Meltdown and Spectre update for WildFire-500 Appliance
vendor_paloalto·2018-05-15·CVSS 5.6
CVE-2017-5715 [MEDIUM] CWE-200 Meltdown and Spectre update for WildFire-500 Appliance
Meltdown and Spectre update for WildFire-500 Appliance
Palo Alto Networks has determined that the WildFire-500 (WF-500) appliance is affected by the vulnerability disclosures known as Meltdown and Spectre, and has completed an update to address these issues. The WF-500 software update is now available to customers that use the WF-500 appliance for on-premise sandboxing. Please note that customers using the WildFire cloud service are NOT impacted by this advisory. (PAN-91139/CVE-2017-5715)
Successful exploitation of this issue may allow reads from the guest image to the host residing in a sandbox appliance. The analysis method utilized by the WF-500 mitigates the impact of this issue.
This issue affects WF-500 (WildFire Appliance) running appliance software versions 8.0.9 and earlier; all
Android
CVE-2017-5715: TLK
vendor_android·2018-05-01·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715: TLK
Android Security Bulletin 2018-05-01
CVE: CVE-2017-5715
Severity: HIGH
Type: ID
Component: TLK
References: A-71686116*
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-04-05·CVSS 7.5
CVE-2017-11089 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3620-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory. (CVE-2017-5715)
It was discovered that the netlink 802.11 configuration interface in the
Linux kernel did not properly validate some attributes passed from
userspace. A local attacker with th
Ubuntu
intel-microcode update
vendor_ubuntu·2018-03-29·CVSS 5.6
CVE-2017-5715 [MEDIUM] intel-microcode update
Title: intel-microcode update
Summary: The system could be made to expose sensitive information.
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory. (CVE-2017-5715)
This update provides the corrected microcode updates required for the
corresponding Linux kernel updates.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-03-15·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USNS 3541-1 and 3523-1 provided mitigations for Spectre and Meltdown
(CVE-2017-5715, CVE-2017-5753, CVE-2017-5754) for the i386, amd64,
and ppc64el architectures in Ubuntu 17.10. This update provides
the corresponding mitigations for the arm64 architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Meltdown. A local attacker could
use this to expose sensitive information, including kernel memory.
(CVE-2017-5754)
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-03-15·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3597-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu 16.04 LTS.
USNS 3541-2 and 3523-2 provided mitigations for Spectre and Meltdown
(CVE-2017-5715, CVE-2017-5753, CVE-2017-5754) for the i386, amd64,
and ppc64el architectures for Ubuntu 16.04 LTS. This update provides
the corresponding mitigations for the arm64 architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Meltdo
BSD
FreeBSD-SA-18:03.speculative_execution: Speculative Execution Vulnerabilities
bsd_advisories·2018-03-14·CVSS 5.6
CVE-2017-5715 [MEDIUM] FreeBSD-SA-18:03.speculative_execution: Speculative Execution Vulnerabilities
FreeBSD-SA-18:03.speculative_execution Security Advisory
The FreeBSD Project
Topic: Speculative Execution Vulnerabilities
Category: core
Module: kernel
Announced: 2018-03-14
Credits: Jann Horn (Google Project Zero); Werner Haas, Thomas
Prescher (Cyberus Technology); Daniel Gruss, Moritz Lipp,
Stefan Mangard, Michael Schwarz (Graz University of
Technology); Paul Kocher; Daniel Genkin (University of
Pennsylvania and University of Maryland), Mike Hamburg
(Rambus); Yuval Yarom (University of Adelaide and Data6)
Affects: All supported versions of FreeBSD.
Corrected: 2018-02-17 18:00:01 UTC (stable/11, 11.1-STABLE)
2018-03-14 04:00:00 UTC (releng/11.1, 11.1-RELEASE-p8)
CVE Name: CVE-2017-5715, CVE-2017-5754
Special Note: Speculative execution vulnerability mitigation is a work
in progress. Th
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2018-03-09·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to expose sensitive information.
USN-3542-1 mitigated CVE-2017-5715 (Spectre Variant 2) for the
amd64 architecture in Ubuntu 14.04 LTS. This update provides the
compiler-based retpoline kernel mitigation for the amd64 and i386
architectures. Original advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory. (CVE-2017-5715)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the ker
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 7.8
CVE-2017-15115 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
ChunYu Wang discovered that a use-after-free vulnerability existed
in the SCTP protocol implementation in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code, (CVE-2017-15115)
Mohamed Ghannam discovered a use-after-free vulnerability in the DCCP
protocol implementation in the Linux kernel. A local attacker could use
this to cause a denial of servic
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 7.8
CVE-2017-15115 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3581-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu 16.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
ChunYu Wang discovered that a use-after-free vulnerability existed
in the SCTP protocol implementation in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash)
or possibly exec
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory.
Instructions: Please note that fully mitigating CVE-2017-5715 (Spectre Variant 2)
requires corresponding processor microcode/firmware updates or,
in virtual environments, hypervisor updates. On i386 and amd64
architectures, the IBRS and IBPB features are required to enable the
kernel mitigations. Ubuntu is working with Intel and AMD to provide
future microcode updates that implement IBRS and IBPB as they are made
a
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 5.5
CVE-2015-8952 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3582-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of serv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 5.5
CVE-2015-8952 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel
did not properly track reference counts when merging buffers. A local
attacker could use this to cause a denial of service (memory e
Ubuntu
QEMU update
vendor_ubuntu·2018-02-07
CVE-2017-5715 QEMU update
Title: QEMU update
Summary: Spectre mitigations were added to QEMU.
It was discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. An attacker in the guest could use
this to expose sensitive guest information, including kernel memory.
This update allows QEMU to expose new CPU features added by microcode
updates to guests on amd64, i386, and s390x. On amd64 and i386, new CPU
models that match the updated microcode features were added with an -IBRS
suffix. Certain environments will require guests to be switched manually to
the new CPU models after microcode updates have been applied to the host.
Instructions: After a standard system update you need to restart all QEMU
Ubuntu
libvirt update
vendor_ubuntu·2018-02-07
CVE-2017-5715 libvirt update
Title: libvirt update
Summary: Spectre mitigations were added to libvirt.
It was discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. An attacker in the guest could use
this to expose sensitive guest information, including kernel memory.
This update allows libvirt to expose new CPU features added by microcode
updates to guests. On amd64 and i386, new CPU models that match the updated
microcode features were added with an -IBRS suffix. Certain environments
will require guests to be switched manually to the new CPU models after
microcode updates have been applied to the host.
Instructions: After a standard system update you need to reboot your computer to make
all
Ubuntu
Linux kernel (KVM) vulnerabilities
vendor_ubuntu·2018-01-29·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (KVM) vulnerabilities
Title: Linux kernel (KVM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. (CVE-2017-5715, CVE-2017-5753)
Instructions: Please note that fully mitigating CVE-2017-5715 (Spectre Variant 2)
requires corresponding processor microcode/firmware updates or,
in virtual environments, hypervisor updates. On i386 and amd64
architectures, the IBRS and IBPB features are required to enable the
kernel mitigations. Ubuntu is working with Intel and AMD to provide
future microcode updates that imple
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Spectre. A local attacker
could use this to expose sensitive information, including kernel
memory. This update provides mitigations for the i386 (CVE-2017-5753
only) and amd64 architectures.
Instructions: Please note that fully mitigating CVE-2017-5715 (Spectre Variant 2)
requires corresponding processor microcode/firmware updates or,
in virtual environments, hypervisor updates. On i386 and amd64
architectures, the IBRS and IBPB features are required to enable the
kernel mitigations. Ubuntu is working with I
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
USN-3542-1 addressed vulnerabilities in the Linux kernel for Ubuntu
14.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for
Ubuntu 12.04 ESM.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Spectre. A local attacker
could use this to expose sensitive information, including kernel
memory. This update provides mitigations for the i386 (CVE-2017-5753
only) and amd64 architectures.
Instructions: Please note that fully mitigating CVE-2017-5715 (Spectre Variant 2)
requires
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
USN-3540-1 addressed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3522-2 mitigated CVE-2017-5754 (Meltdow
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3523-1 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in Ubuntu 17.10. This update provides the corresponding
mitigations for the ppc64el architecture. Original advisory details:
Jann Horn discovered that microprocessors utilizing speculative
execution a
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
USN-3541-1 addressed vulnerabilities in the Linux kernel for Ubuntu
17.10. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu
16.04 LTS.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3523-2 mitigated CVE-2017-5754 (Meltdown) for the amd6
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3522-1 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in Ubuntu 16.04 LTS. This update provides the
corresponding mitigations for the ppc64el architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative
executi
Ubuntu
Intel Microcode regression
vendor_ubuntu·2018-01-22·CVSS 5.6
[MEDIUM] Intel Microcode regression
Title: Intel Microcode regression
Summary: USN-3531-1 introduced regressions in intel-microcode.
USN-3531-1 updated Intel microcode to the 20180108 release. Regressions
were discovered in the microcode updates which could cause system
instability on certain hardware platforms. At the request of Intel, we have
reverted to the previous packaged microcode version, the 20170707 release.
Original advisory details:
It was discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory. (CVE-2017-5715)
This update provides the microcode updates required for the corresponding
Linux kernel upda
Ubuntu
Intel Microcode update
vendor_ubuntu·2018-01-11·CVSS 5.6
CVE-2017-5715 [MEDIUM] Intel Microcode update
Title: Intel Microcode update
Summary: The system could be made to expose sensitive information.
It was discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory. (CVE-2017-5715)
This update provides the microcode updates required for the corresponding
Linux kernel updates.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
WebKitGTK+ vulnerabilities
vendor_ubuntu·2018-01-11·CVSS 5.6
CVE-2017-5715 [MEDIUM] WebKitGTK+ vulnerabilities
Title: WebKitGTK+ vulnerabilities
Summary: WebKitGTK+ could be made to expose sensitive information.
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5753, CVE-2017-5715)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.
Apple
CVE-2017-5753: Safari 11.0.2
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753: Safari 11.0.2
Apple Security Update: About the security content of Safari 11.0.2
Product: Safari
Version: 11.0.2
CVE: CVE-2017-5753
Component: Safari 11.0.2
Description: Safari 11.0.2 includes security improvements to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5715: iOS 11.2.2
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715: iOS 11.2.2
Apple Security Update: About the security content of iOS 11.2.2
Product: iOS
Version: 11.2.2
CVE: CVE-2017-5715
Component: About Apple security updates
Description: iOS 11.2.2 includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5715: macOS High Sierra 10.13.2 Supplemental Update
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715: macOS High Sierra 10.13.2 Supplemental Update
Apple Security Update: About the security content of macOS High Sierra 10.13.2 Supplemental Update
Product: macOS High Sierra 10.13.2 Supplemental Update
CVE: CVE-2017-5715
Component: About Apple security updates
Description: macOS High Sierra 10.13.2 Supplemental Update includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5753: macOS High Sierra 10.13.2 Supplemental Update
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753: macOS High Sierra 10.13.2 Supplemental Update
Apple Security Update: About the security content of macOS High Sierra 10.13.2 Supplemental Update
Product: macOS High Sierra 10.13.2 Supplemental Update
CVE: CVE-2017-5753
Component: About Apple security updates
Description: macOS High Sierra 10.13.2 Supplemental Update includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5753: iOS 11.2.2
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753: iOS 11.2.2
Apple Security Update: About the security content of iOS 11.2.2
Product: iOS
Version: 11.2.2
CVE: CVE-2017-5753
Component: About Apple security updates
Description: iOS 11.2.2 includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5715: Safari 11.0.2
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715: Safari 11.0.2
Apple Security Update: About the security content of Safari 11.0.2
Product: Safari
Version: 11.0.2
CVE: CVE-2017-5715
Component: Safari 11.0.2
Description: Safari 11.0.2 includes security improvements to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2018-01-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to expose sensitive information.
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5715,
CVE-2017-5753, CVE-2017-5754).
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Palo Alto
PAN-SA-2018-0001 Information about Meltdown and Spectre findings
vendor_paloalto·2018-01-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] CWE-200 PAN-SA-2018-0001 Information about Meltdown and Spectre findings
PAN-SA-2018-0001 Information about Meltdown and Spectre findings
Palo Alto Networks is aware of recent vulnerability disclosures, known as Meltdown and Spectre, that affect modern CPU architectures. At this time, our findings show that these vulnerabilities pose no increased risk to Palo Alto Networks PAN-OS devices. (CVE-2017-5715, CVE-2017-5753, and CVE-2017-5754). This security advisory will be updated as more information becomes available or if there are changes in the impact of these vulnerabilities. PAN-OS/Panorama platforms are not directly impacted by these vulnerabilities, as successful
CVEs: CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
Affected products: PAN-OS, Panorama
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities
vendor_cisco·2018-01-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] CWE-200 CPU Side-Channel Information Disclosure Vulnerabilities
CPU Side-Channel Information Disclosure Vulnerabilities
On January 3, 2018, researchers disclosed three vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged local attacker, in specific circumstances, to read privileged memory belonging to other processes or memory allocated to the operating system kernel.
The first two vulnerabilities, CVE-2017-5753 and CVE-2017-5715, are collectively known as Spectre. The third vulnerability, CVE-2017-5754, is known as Meltdown. The vulnerabilities are all variants of the same attack and differ in the way that speculative execution is exploited.
To exploit any
Red Hat
hw: cpu: speculative execution branch target injection
vendor_redhat·2018-01-03·CVSS 5.6
CVE-2017-5715 [MEDIUM] CWE-226 hw: cpu: speculative execution branch target injection
hw: cpu: speculative execution branch target injection
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited. Variant CVE-2017-5715 triggers the speculative execution by utilizing branch target injection. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allo
VMware
VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution.
vendor_vmware·2018-01-03·CVSS 5.6
CVE-2017-5715 [MEDIUM] VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution.
VMSA-2018-0002: VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution.
VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution. Note: This document will focus on the Hypervisor-Specific Mitigations for the known variants of CVE-2017-5753 and CVE-2017-5715. Please review KB52245 for a holistic view on VMware’s response. 2. Relevant Products VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion) 3. Problem Description Bounds-Check bypass and Branch Target Injection issues CPU data cache timing can be abused to efficiently leak information out of mis-speculated CPU execution, leading to (at worst) arbitrary virtual memory read vulnerabilities a
Debian
CVE-2017-5715: amd64-microcode - Systems with microprocessors utilizing speculative execution and indirect branch...
vendor_debian·2017·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715: amd64-microcode - Systems with microprocessors utilizing speculative execution and indirect branch...
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 3.20180515.1)
bullseye: resolved (fixed in 3.20180515.1)
forky: resolved (fixed in 3.20180515.1)
sid: resolved (fixed in 3.20180515.1)
trixie: resolved (fixed in 3.20180515.1)
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities
vendor_cisco
CVE-2017-5715 CPU Side-Channel Information Disclosure Vulnerabilities
CVE-2017-5715: CPU Side-Channel Information Disclosure Vulnerabilities
On January 3, 2018, researchers disclosed three vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged local attacker, in specific circumstances, to read privileged memory belonging to other processes or memory allocated to the operating system kernel. The first two vulnerabilities, CVE-2017-5753 and CVE-2017-5715, are collectively known as Spectre . The third vulnerability, CVE-2017-5754, is known as Meltdown . The vulnerabilities are all variants of the same attack and differ in the way that speculative execution is exploited.
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities
vendor_cisco
CVE-2017-5753 CPU Side-Channel Information Disclosure Vulnerabilities
CVE-2017-5753: CPU Side-Channel Information Disclosure Vulnerabilities
On January 3, 2018, researchers disclosed three vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged local attacker, in specific circumstances, to read privileged memory belonging to other processes or memory allocated to the operating system kernel. The first two vulnerabilities, CVE-2017-5753 and CVE-2017-5715, are collectively known as Spectre . The third vulnerability, CVE-2017-5754, is known as Meltdown . The vulnerabilities are all variants of the same attack and differ in the way that speculative execution is exploited.
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities
vendor_cisco
CVE-2017-5754 CPU Side-Channel Information Disclosure Vulnerabilities
CVE-2017-5754: CPU Side-Channel Information Disclosure Vulnerabilities
On January 3, 2018, researchers disclosed three vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged local attacker, in specific circumstances, to read privileged memory belonging to other processes or memory allocated to the operating system kernel. The first two vulnerabilities, CVE-2017-5753 and CVE-2017-5715, are collectively known as Spectre . The third vulnerability, CVE-2017-5754, is known as Meltdown . The vulnerabilities are all variants of the same attack and differ in the way that speculative execution is exploited.
GHSA
GHSA-4g2c-qjxv-9c24: LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs
ghsa_unreviewed·2022-03-12·CVSS 5.6
CVE-2021-26401 [MEDIUM] GHSA-4g2c-qjxv-9c24: LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
OSV
CVE-2021-26401: LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs
osv·2022-03-11·CVSS 5.6
CVE-2021-26401 [MEDIUM] CVE-2021-26401: LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
OSV
intel-microcode vulnerabilities
osv·2021-06-09·CVSS 5.6
CVE-2020-24489 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel processors may not properly invalidate
cache entries used by Intel Virtualization Technology for Directed I/O
(VT-d). This may allow a local user to perform a privilege escalation
attack. (CVE-2020-24489)
Joseph Nuzman discovered that some Intel processors may not properly apply
EIBRS mitigations (originally developed for CVE-2017-5715) and hence may
allow unauthorized memory reads via sidechannel attacks. A local attacker
could use this to expose sensitive information, including kernel
memory. (CVE-2020-24511)
Travis Downs discovered that some Intel processors did not properly flush
cache-lines for trivial-data values. This may allow an unauthorized user to
infer the presence of these trivial-data-cache-lines via timing
OSV
linux-azure vulnerabilities
osv·2018-10-23·CVSS 5.6
CVE-2018-17182 [MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
USN-3777-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
%LTS. This update provides the corresponding updates for the
Linux kernel for Azure Cloud systems.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing sp
OSV
amd64-microcode regression
osv·2018-07-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] amd64-microcode regression
amd64-microcode regression
USN-3690-1 provided updated microcode for AMD processors to address
CVE-2017-5715 (aka Spectre). Unfortunately, the update caused some
systems to fail to boot. This update reverts the update for Ubuntu
14.04 LTS.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory.
This update provides the microcode updates for AMD 17H family
processors required for the corresponding Linux kernel updates.
Kernel
arm64: KVM: Use SMCCC_ARCH_WORKAROUND_1 for Falkor BP hardening
kernel_security·2018-04-10·CVSS 5.6
CVE-2017-5715 [MEDIUM] arm64: KVM: Use SMCCC_ARCH_WORKAROUND_1 for Falkor BP hardening
arm64: KVM: Use SMCCC_ARCH_WORKAROUND_1 for Falkor BP hardening
The function SMCCC_ARCH_WORKAROUND_1 was introduced as part of SMC
V1.1 Calling Convention to mitigate CVE-2017-5715. This patch uses
the standard call SMCCC_ARCH_WORKAROUND_1 for Falkor chips instead
of Silicon provider service ID 0xC2001700.
Cc: # 4.14+
Signed-off-by: Shanker Donthineni
[maz: reworked errata framework integration]
Signed-off-by: Marc Zyngier
Signed-off-by: Will Deacon
OSV
intel-microcode update
osv·2018-03-29·CVSS 5.6
CVE-2017-5715 [MEDIUM] intel-microcode update
intel-microcode update
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory. (CVE-2017-5715)
This update provides the corrected microcode updates required for the
corresponding Linux kernel updates.
OSV
linux-hwe vulnerabilities
osv·2018-03-15·CVSS 5.6
CVE-2017-5715 [MEDIUM] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3597-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu 16.04 LTS.
USNS 3541-2 and 3523-2 provided mitigations for Spectre and Meltdown
(CVE-2017-5715, CVE-2017-5753, CVE-2017-5754) for the i386, amd64,
and ppc64el architectures for Ubuntu 16.04 LTS. This update provides
the corresponding mitigations for the arm64 architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Meltdown. A local attacker could
use this to expose sensitive information, including ker
OSV
linux vulnerability
osv·2018-03-09·CVSS 5.6
CVE-2017-5715 [MEDIUM] linux vulnerability
linux vulnerability
USN-3542-1 mitigated CVE-2017-5715 (Spectre Variant 2) for the
amd64 architecture in Ubuntu 14.04 LTS. This update provides the
compiler-based retpoline kernel mitigation for the amd64 and i386
architectures. Original advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory. (CVE-2017-5715)
Kernel
arm64: KVM: Use SMCCC_ARCH_WORKAROUND_1 for Falkor BP hardening
kernel_security·2018-03-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] arm64: KVM: Use SMCCC_ARCH_WORKAROUND_1 for Falkor BP hardening
arm64: KVM: Use SMCCC_ARCH_WORKAROUND_1 for Falkor BP hardening
The function SMCCC_ARCH_WORKAROUND_1 was introduced as part of SMC
V1.1 Calling Convention to mitigate CVE-2017-5715. This patch uses
the standard call SMCCC_ARCH_WORKAROUND_1 for Falkor chips instead
of Silicon provider service ID 0xC2001700.
Cc: # 4.14+
Signed-off-by: Shanker Donthineni
Signed-off-by: Marc Zyngier
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-02-22·CVSS 5.5
CVE-2017-17712 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel
did not properly track reference counts when merging buffers. A local
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2017-1219
OSV
linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
osv·2018-02-22·CVSS 7.8
[HIGH] linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
USN-3581-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu 16.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
ChunYu Wang discovered that a use-after-free vulnerability existed
in the SCTP protocol implementation in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code, (CVE-2017-15115)
Mohamed G
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-02-22·CVSS 5.5
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3582-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsys
Kernel
arm64: KVM: Report SMCCC_ARCH_WORKAROUND_1 BP hardening support
kernel_security·2018-02-06·CVSS 5.6
CVE-2017-5715 [MEDIUM] arm64: KVM: Report SMCCC_ARCH_WORKAROUND_1 BP hardening support
arm64: KVM: Report SMCCC_ARCH_WORKAROUND_1 BP hardening support
A new feature of SMCCC 1.1 is that it offers firmware-based CPU
workarounds. In particular, SMCCC_ARCH_WORKAROUND_1 provides
BP hardening for CVE-2017-5715.
If the host has some mitigation for this issue, report that
we deal with it using SMCCC_ARCH_WORKAROUND_1, as we apply the
host workaround on every guest exit.
Tested-by: Ard Biesheuvel
Reviewed-by: Christoffer Dall
Signed-off-by: Marc Zyngier
Signed-off-by: Catalin Marinas
OSV
linux-kvm vulnerabilities
osv·2018-01-29·CVSS 5.6
CVE-2017-5715 [MEDIUM] linux-kvm vulnerabilities
linux-kvm vulnerabilities
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. (CVE-2017-5715, CVE-2017-5753)
OSV
linux, linux-aws, linux-euclid vulnerabilities
osv·2018-01-23·CVSS 5.6
CVE-2017-5753 [MEDIUM] linux, linux-aws, linux-euclid vulnerabilities
linux, linux-aws, linux-euclid vulnerabilities
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3522-1 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in Ubuntu 16.04 LTS. This update provides the
corresponding mitigations for the ppc64el architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative
execution and indirect branch prediction may allow unauthorized me
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-01-23·CVSS 5.6
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3540-1 addressed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3522-2 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in the Linux Hardware Enablement (HWE) kernel
OSV
linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
osv·2018-01-23·CVSS 5.6
[MEDIUM] linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
USN-3541-1 addressed vulnerabilities in the Linux kernel for Ubuntu
17.10. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu
16.04 LTS.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3523-2 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in the Linux Hardware Enablement (HW
OSV
intel-microcode regression
osv·2018-01-22·CVSS 5.6
[MEDIUM] intel-microcode regression
intel-microcode regression
USN-3531-1 updated Intel microcode to the 20180108 release. Regressions
were discovered in the microcode updates which could cause system
instability on certain hardware platforms. At the request of Intel, we have
reverted to the previous packaged microcode version, the 20170707 release.
Original advisory details:
It was discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory. (CVE-2017-5715)
This update provides the microcode updates required for the corresponding
Linux kernel updates.
Kernel
KVM: PPC: Book3S: Provide information about hardware/firmware CVE workarounds
kernel_security·2018-01-15·CVSS 5.6
CVE-2017-5715 [MEDIUM] KVM: PPC: Book3S: Provide information about hardware/firmware CVE workarounds
KVM: PPC: Book3S: Provide information about hardware/firmware CVE workarounds
This adds a new ioctl, KVM_PPC_GET_CPU_CHAR, that gives userspace
information about the underlying machine's level of vulnerability
to the recently announced vulnerabilities CVE-2017-5715,
CVE-2017-5753 and CVE-2017-5754, and whether the machine provides
instructions to assist software to work around the vulnerabilities.
The ioctl returns two u64 words describing characteristics of the
CPU and required software behaviour respectively, plus two mask
words which indicate which bits have been filled in by the kernel,
for extensibility. The bit definitions are the same as for the
new H_GET_CPU_CHARACTERISTICS hypercall.
There is also a new capability, KVM_CAP_PPC_GET_CPU_CHAR, which
indicates whether the new ioctl
OSV
intel-microcode update
osv·2018-01-11·CVSS 5.6
CVE-2017-5715 [MEDIUM] intel-microcode update
intel-microcode update
It was discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory. (CVE-2017-5715)
This update provides the microcode updates required for the corresponding
Linux kernel updates.
OSV
webkit2gtk vulnerabilities
osv·2018-01-11·CVSS 5.6
CVE-2017-5753 [MEDIUM] webkit2gtk vulnerabilities
webkit2gtk vulnerabilities
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5753, CVE-2017-5715)
Kernel
bpf: introduce BPF_JIT_ALWAYS_ON config
kernel_security·2018-01-09·CVSS 5.6
CVE-2017-5715 [MEDIUM] bpf: introduce BPF_JIT_ALWAYS_ON config
bpf: introduce BPF_JIT_ALWAYS_ON config
The BPF interpreter has been used as part of the spectre 2 attack CVE-2017-5715.
A quote from goolge project zero blog:
"At this point, it would normally be necessary to locate gadgets in
the host kernel code that can be used to actually leak data by reading
from an attacker-controlled location, shifting and masking the result
appropriately and then using the result of that as offset to an
attacker-controlled address for a load. But piecing gadgets together
and figuring out which ones work in a speculation context seems annoying.
So instead, we decided to use the eBPF interpreter, which is built into
the host kernel - while there is no legitimate way to invoke it from inside
a VM, the presence of the code in the host kernel's text section is suffic
Kernel
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
kernel_security·2018-01-06
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Pull KVM fixes from Radim Krčmář:
"s390:
- Two fixes for potential bitmap overruns in the cmma migration code
x86:
- Clear guest provided GPRs to defeat the Project Zero PoC for CVE
2017-5715"
* tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm:
kvm: vmx: Scrub hardware GPRs at VM-exit
KVM: s390: prevent buffer overrun on memory hotplug during migration
KVM: s390: fix cmma migration for multiple memory slots
OSV
firefox vulnerabilities
osv·2018-01-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5715,
CVE-2017-5753, CVE-2017-5754).
OSV
CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an att
osv·2018-01-04·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an att
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Project0
Reading privileged memory with a side-channel - Project Zero
project_zero·2018-01-01·CVSS 5.6
CVE-2017-5715 [MEDIUM] Reading privileged memory with a side-channel - Project Zero
Posted by Jann Horn, Project Zero
We have discovered that CPU data cache timing can be abused to efficiently leak information out of mis-speculated execution, leading to (at worst) arbitrary virtual memory read vulnerabilities across local security boundaries in various contexts.
Variants of this issue are known to affect many modern processors, including certain processors by Intel, AMD and ARM. For a few Intel and AMD CPU models, we have exploits that work against real software. We reported this issue to Intel, AMD and ARM on 2017-06-01 [1].
So far, there are three known variants of the issue:
-
Variant 1: bounds check bypass (CVE-2017-5753)
-
Variant 2: branch target injection (CVE-2017-5715)
-
Variant 3: rogue data cache load (CVE-2017-5754)
Before the issues described he
Suricata
ET EXPLOIT Possible Spectre PoC Download In Progress
suricata·2018-01-10
CVE-2017-5753 ET EXPLOIT Possible Spectre PoC Download In Progress
ET EXPLOIT Possible Spectre PoC Download In Progress
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Spectre PoC Download In Progress"; flow:established,to_client; flowbits:isset,ET.http.binary; file.data; content:"|E7 03 00 00|"; content:"|48 0F AE|"; distance:17; within:9; pcre:"/^[\x30-\x3f\x7D]/Rs"; content:"|48 0F AE 3D|"; distance:41; within:10; content:"|48 98|"; distance:64; within:22; content:"|0F 01 F9|"; distance:50; within:9; content:"|0F 01 F9|"; distance:30; within:9; reference:cve,2017-5753; reference:cve,2017-5715; classtype:attempted-admin; sid:2025196; rev:3; metadata:attack_target Client_Endpoint, created_at 2018_01_10, cve CVE_2017_5753, deployment Perimeter, malware_family Spectre_Exploit, performance_impact Low, confidence Medium, signat
Suricata
ET WEB_CLIENT Spectre Exploit Javascript
suricata·2018-01-09
CVE-2017-5753 ET WEB_CLIENT Spectre Exploit Javascript
ET WEB_CLIENT Spectre Exploit Javascript
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Spectre Exploit Javascript"; flow:established,to_client; file.data; content:"0x1000000"; fast_pattern; pcre:"/(?[^=\s]*)\s*=\s*0x1000000.+?\x28\s*\x28\s*\x28\s*\w+\s*<<\s*12\s*\x29\s*\|\s*0\s*\x29\s*\+\s*(?P=var1)\s*\x29\s*\|\s*0/s"; reference:cve,2017-5753; reference:cve,2017-5715; reference:url,github.com/cgvwzq/spectre; classtype:attempted-user; sid:2025188; rev:7; metadata:affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2018_01_09, cve CVE_2017_5753, deployment Perimeter, performance_impact Moderate, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_03_14;)
Sentinelone
Black Basta
blogs_sentinelone·2022-11-30
Black Basta
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Tenable
Spectre and Meltdown
blogs_tenable·2022-11-07·CVSS 5.6
[MEDIUM] Spectre and Meltdown
by Carole Fennelly November 7, 2022
A compromised processor is one of the most serious attack vectors on any platform. The hardware bugs known as Spectre and Meltdown affect modern processors by accessing information found in the system's memory. The Spectre and Meltdown dashboard provides insight into which systems are affected by these hardware bugs.
The Spectre and Meltdown bugs use side channels to obtain information from the accessed memory location. Spectre allows an application to force another application to access arbitrary portions of its memory, which can then be read through a side channel. This unique side channel attack uses speculative execution, a technique used by high-speed processors, to increase performance by guessing likely future execution paths and preemptively ex
Tenable
How VPR Helped Prioritize the Most Dangerous CVEs in 2019
blogs_tenable·2020-04-30
How VPR Helped Prioritize the Most Dangerous CVEs in 2019
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Getting Started with Tenable.sc Using SLA's
blogs_tenable·2020-01-10
Getting Started with Tenable.sc Using SLA's
by Cody Dumont January 10, 2020
Service Level Agreements often change from one organizations to the next, however meeting SLA’s is a common issue among organizations industry wide. Tenable.sc provides a vast array of data that provides vulnerability management SLA metrics, but where can the CISO get started? This dashboard is commonly used by the sales team at Tenable to help coach organizations to meet SLA’s. The components in this dashboard are grouped in 3-series, which provide a CISO and Risk Manager with a starting point for SLA analysis.
The first few rows provide a detailed analysis on SLA’s for vulnerabilities based on Common Vulnerability Scoring System (CVSS) and Vulnerability Priority Rating (VPR). Traditionally many SLA’s are based on Microsoft’s Patch Tuesday and provide org
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
CVE-2018-
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
- Introduction
- Targeted attack campaigns
- Mobile APT campaigns
- Exploits
- Browser extensions – extending the reach of cybercriminals
- The World Cup of fraud
- Financial fraud on an industrial scale
- Ransomware – still a threat
- Asacub and banking Trojans
- Smart doesn’t mean secure
- Our data in their hands
Authors
- David Emm
- Victor Chebyshev
- Kaspersky Security Bulletin 2018. Statistics
- Kaspersky Security Bulletin 2018. Story of the year: miners
- Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses a
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
Introduction
Targeted attack campaigns
Mobile APT campaigns
Exploits
Browser extensions – extending the reach of cybercriminals
The World Cup of fraud
Financial fraud on an industrial scale
Ransomware – still a threat
Asacub and banking Trojans
Smart doesn’t mean secure
Our data in their hands
Authors
David Emm
Victor Chebyshev
Kaspersky Security Bulletin 2018. Statistics
Kaspersky Security Bulletin 2018. Story of the year: miners
Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses and consumers provide
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15·CVSS 5.6
[MEDIUM] 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Blog / Research
Subscribe
# 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Pablo Ramos
November 15, 2018
5 Min Read
The classes of vulnerabilities that brought us Meltdown and Spectre are not going away anytime soon. Here’s what you need to know about Speculative Execution vulnerabilities, with our guidance on steps you can take to reduce your risk.
Spectre and Meltdown generated a lot of confusion and discussion in the security world when they first hit the news. Understanding the risks associated with speculative execution vulnerabilities will help organizations prioritize and communicate effectively about their exposure. In this post, we present what it is known, how it affects companies and ways to stay ahead in the game.
## Start from the beginning…
Speculative Ex
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15
5W1H: Speculative Side Channel Vulnerabilities De-mystified
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution Q1 2018
blogs_securelist·2018-05-14
IT threat evolution Q1 2018
Authors
- David Emm
## Targeted attacks and malware campaigns
### Skygofree: sophisticated mobile surveillance
In January, we uncovered a sophisticated mobile implant that provides attackers with remote control of infected Android devices. The malware, called Skygofree (after one of the domains it uses), is a targeted cyber-surveillance tool that has been in development since 2014. The malware is spread by means of spoofed web pages that mimic leading mobile providers. The campaign is ongoing and our telemetry indicates that there have been several victims, all in Italy. We feel confident that the developer of Skygofree is an Italian IT company that works on surveillance solutions.
The latest version of Skygofree includes functionality that has so far not been seen in the wild. Featur
Securelist
IT threat evolution Q1 2018
blogs_securelist·2018-05-14
IT threat evolution Q1 2018
Authors
David Emm
## Targeted attacks and malware campaigns
## Skygofree: sophisticated mobile surveillance
In January, we uncovered a sophisticated mobile implant that provides attackers with remote control of infected Android devices. The malware, called Skygofree (after one of the domains it uses), is a targeted cyber-surveillance tool that has been in development since 2014. The malware is spread by means of spoofed web pages that mimic leading mobile providers. The campaign is ongoing and our telemetry indicates that there have been several victims, all in Italy. We feel confident that the developer of Skygofree is an Italian IT company that works on surveillance solutions.
The latest version of Skygofree includes functionality that has so far not been seen in the wild. Features
Qualys
Apple in the InfoSec Spotlight, as GitHub Falls Prey to Amplified DDoS Attack
blogs_qualys·2018-03-02
Apple in the InfoSec Spotlight, as GitHub Falls Prey to Amplified DDoS Attack
Apple has been all over InfoSec news in the past week or so, along with Spectre / Meltdown developments, a tax season scam alert from the feds, and an apparent solution to the Winter Olympics’ hack whodunit. In addition, researchers warned about a new trend of using Memcached servers to significantly boost DDoS attacks, as GitHub became a victim of this new tactic.
## Apple under siege
The second half of February was intense for Apple on the security front. A digital forensics vendor claimed having the ability to unlock all iPhone models, including the X, while a researcher warned about a Trojan targeting MacOs computers that’s not detected by anti-virus products. Oh, and Apple had to squash another one of those pesky bugs that let people crash iPhones via texting.
Unlocking iPhones
Fo
Qualys
Apple in the InfoSec Spotlight, as GitHub Falls Prey to Amplified DDoS Attack | Qualys
blogs_qualys·2018-03-02
Apple in the InfoSec Spotlight, as GitHub Falls Prey to Amplified DDoS Attack | Qualys
Apple has been all over InfoSec news in the past week or so, along with Spectre / Meltdown developments, a tax season scam alert from the feds, and an apparent solution to the Winter Olympics’ hack whodunit. In addition, researchers warned about a new trend of using Memcached servers to significantly boost DDoS attacks, as GitHub became a victim of this new tactic.
### Apple under siege
A digital forensics vendor claims it can crack iOS devices, including the iPhone X, pictured here. (Photo credit: Apple)
The second half of February was intense for Apple on the security front. A digital forensics vendor claimed having the ability to unlock all iPhone models, including the X, while a researcher warned about a Trojan targeting MacOs computers that’s not detected by anti-virus products. Oh
Qualys
Olympics, Patch Tuesday & Meltdown/Spectre | Qualys
blogs_qualys·2018-02-16
Olympics, Patch Tuesday & Meltdown/Spectre | Qualys
This week offered a representative sampling of different corners of the cyber security world: The monthly Patch Tuesday, a brazen attack against the Olympics, new Meltdown and Spectre concerns, and a boost for Intel’s bug bounty program.
Oh, and the gargantuan Equifax data breach may have been even bigger than previously thought.
### Winter Olympics hack confirmed
The 2018 Winter Olympics in Pyeongchang, South Korea are in full swing, featuring the world’s best ice skaters, skiers, hockey players and snowboarders, and also attracting, unfortunately, malicious hackers.
Attackers’ goals seem to be to disrupt the games in a variety of ways by interfering with and disabling IT systems.
Officials confirmed that hackers disrupted the opening ceremony by knocking the Winter Olympics’ website
Qualys
Hackers Hit the Olympics, While Patch Tuesday and Meltdown / Spectre Keep IT Departments On Edge
blogs_qualys·2018-02-16
Hackers Hit the Olympics, While Patch Tuesday and Meltdown / Spectre Keep IT Departments On Edge
This week offered a representative sampling of different corners of the cyber security world: The monthly Patch Tuesday, a brazen attack against the Olympics, new Meltdown and Spectre concerns, and a boost for Intel’s bug bounty program.
Oh, and the gargantuan Equifax data breach may have been even bigger than previously thought.
## Winter Olympics hack confirmed
The 2018 Winter Olympics in Pyeongchang, South Korea are in full swing, featuring the world’s best ice skaters, skiers, hockey players and snowboarders, and also attracting, unfortunately, malicious hackers.
Attackers’ goals seem to be to disrupt the games in a variety of ways by interfering with and disabling IT systems.
Officials confirmed that hackers disrupted the opening ceremony by knocking the Winter Olympics’ website
Qualys
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug
blogs_qualys·2018-02-09
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug
It’s been a busy week in InfoSec land, as Intel released a new Spectre patch, iOS source code was leaked online, and a zero-day Flash bug got exploited in the wild.
Also making noise these past few days: A major security hole in the Grammarly web app, WordPress updates tripping over each other, and a data breach at a Swiss telecom company.
As has been the case these past few weeks, we’ll lead off with the latest on Meltdown and Spectre, the hardware vulnerabilities whose disclosure on Jan. 3 sent shockwaves through the IT industry due to their scope and severity, and which are expected to remain an issue for years.
## Intel mitigates Spectre vulnerability with Skylake update
For a change, the latest Meltdown / Spectre development is encouraging: On Wednesday, Intel announced some progr
Qualys
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug | Qualys
blogs_qualys·2018-02-09
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug | Qualys
It’s been a busy week in InfoSec land, as Intel released a new Spectre patch, iOS source code was leaked online, and a zero-day Flash bug got exploited in the wild.
Also making noise these past few days: A major security hole in the Grammarly web app, WordPress updates tripping over each other, and a data breach at a Swiss telecom company.
As has been the case these past few weeks, we’ll lead off with the latest on Meltdown and Spectre, the hardware vulnerabilities whose disclosure on Jan. 3 sent shockwaves through the IT industry due to their scope and severity, and which are expected to remain an issue for years.
### Intel mitigates Spectre vulnerability with Skylake update
For a change, the latest Meltdown / Spectre development is encouraging: On Wednesday, Intel announced some prog
Qualys
Meltdown / Spectre: New Concerns Over Intel Patches, as Hackers Test Exploits
blogs_qualys·2018-02-02·CVSS 5.6
[MEDIUM] Meltdown / Spectre: New Concerns Over Intel Patches, as Hackers Test Exploits
This week brought new developments in the Meltdown / Spectre saga, including more concerns about Intel’s buggy patches, and mounting evidence that hackers are trying to create exploits for the vulnerabilities.
It seemed that after weeks of complaints and confusion , Intel’s issue had hit bottom and was headed for a resolution on Monday of last week. That’s when the company said its firmware updates for Broadwell and Haswell CPUs shouldn’t be installed anymore , because, as many customers had reported, they made systems behave erratically, including unexpectedly rebooting.
At the time, Intel said it had discovered the “root cause” for the firmware’s problems, and was already actively developing new updates. However, another shoe was about to drop. Three days later Intel acknowledged in it
Qualys
Meltdown / Spectre: New Concerns Over Intel Patches, as Hackers Test Exploits | Qualys
blogs_qualys·2018-02-02·CVSS 5.6
[MEDIUM] Meltdown / Spectre: New Concerns Over Intel Patches, as Hackers Test Exploits | Qualys
This week brought new developments in the Meltdown / Spectre saga, including more concerns about Intel’s buggy patches, and mounting evidence that hackers are trying to create exploits for the vulnerabilities.
It seemed that after weeks of complaints and confusion, Intel’s issue had hit bottom and was headed for a resolution on Monday of last week. That’s when the company said its firmware updates for Broadwell and Haswell CPUs shouldn’t be installed anymore, because, as many customers had reported, they made systems behave erratically, including unexpectedly rebooting.
At the time, Intel said it had discovered the “root cause” for the firmware’s problems, and was already actively developing new updates. However, another shoe was about to drop. Three days later Intel acknowledged in its
Fortinet
Meltdown/Spectre Update
blogs_fortinet·2018-01-30·CVSS 5.6
CVE-2017-5715 [MEDIUM] Meltdown/Spectre Update
FORTIGUARD LABS THREAT RESEARCH
Meltdown/Spectre Update
By FortiGuard SE Team | January 30, 2018
Earlier this month, three major chip manufacturers announced that vulnerabilities known as Meltdown and Spectre (CVE-2017-5715, CVE-2017-5753 and CVE-2017-5754) affected processors deployed in millions of devices.
For the past year or so, FortiGuard Labs has been tracking the efforts of cybercriminals to develop new attacks designed to exploit known vulnerabilities. As detailed in our Fortinet Threat Report for Q2 of 2017, a full 90% of organizations recorded exploits for vulnerabilities that were three or more years old. Even 10+ years after a flaw’s release, 60% of firms still see related attacks.
The rate at which the cybercriminal community is targeting known vulnerabilities is clearly
Qualys
Meltdown/Spectre: Intel Nixes Patches, Tech CEOs Questioned on Information Blackout
blogs_qualys·2018-01-26
Meltdown/Spectre: Intel Nixes Patches, Tech CEOs Questioned on Information Blackout
IT departments and tech vendors continued grappling with Spectre and Meltdown this week, as Intel pulled its glitchy patches and the U.S. Congress questioned the vulnerability disclosures’ timing and scope.
Spectre and Meltdown aren’t typical vulnerabilities for a number of reasons, and as a result, they’ve proven problematic to deal with. Intel, whose products are the most impacted, has had a particularly rocky time crafting its firmware updates for mitigating the bugs.
After receiving multiple complaints from customers, in particular data center operators, that the firmware updates for Broadwell and Haswell CPUs were causing systems to unexpectedly reboot, Intel on Monday finally deep-sixed them .
“We recommend that OEMs, cloud service providers, system manufacturers, software vendors
Qualys
Meltdown/Spectre: Intel Nixes Patches, Tech CEOs Questioned on Information Blackout | Qualys
blogs_qualys·2018-01-26
Meltdown/Spectre: Intel Nixes Patches, Tech CEOs Questioned on Information Blackout | Qualys
IT departments and tech vendors continued grappling with Spectre and Meltdown this week, as Intel pulled its glitchy patches and the U.S. Congress questioned the vulnerability disclosures’ timing and scope.
Spectre and Meltdown aren’t typical vulnerabilities for a number of reasons, and as a result, they’ve proven problematic to deal with. Intel, whose products are the most impacted, has had a particularly rocky time crafting its firmware updates for mitigating the bugs.
After receiving multiple complaints from customers, in particular data center operators, that the firmware updates for Broadwell and Haswell CPUs were causing systems to unexpectedly reboot, Intel on Monday finally deep-sixed them.
“We recommend that OEMs, cloud service providers, system manufacturers, software vendors
Qualys
Meltdown and Spectre Aren’t Business as Usual | Qualys
blogs_qualys·2018-01-18·CVSS 5.6
[MEDIUM] Meltdown and Spectre Aren’t Business as Usual | Qualys
The new year brought a new vulnerability type — the CPU-based Meltdown and Spectre bugs — that’s forcing vendors and IT departments to modify long-standing ways of identifying threats, prioritizing remediation, managing patches and evaluating risk.
“Meltdown and Spectre are different vulnerabilities from what you’re used to seeing,” Jimmy Graham, a Product Management Director at Qualys, said during a webcast on Wednesday.
As a result, it’s essential for organizations to fully understand the nature of these vulnerabilities, stay on top of the latest information, and analyze the vulnerabilities’ impact in their IT environments, in order to stay as safe as possible.
“It’s not a simple [process] of just install a patch and you’re done,” he said.
### A different animal
Graham outlined a nu
Qualys
Meltdown and Spectre Aren’t Business as Usual
blogs_qualys·2018-01-18·CVSS 5.6
[MEDIUM] Meltdown and Spectre Aren’t Business as Usual
The new year brought a new vulnerability type — the CPU-based Meltdown and Spectre bugs — that’s forcing vendors and IT departments to modify long-standing ways of identifying threats, prioritizing remediation, managing patches and evaluating risk.
“Meltdown and Spectre are different vulnerabilities from what you’re used to seeing,” Jimmy Graham, a Product Management Director at Qualys, said during a webcast on Wednesday.
As a result, it’s essential for organizations to fully understand the nature of these vulnerabilities, stay on top of the latest information, and analyze the vulnerabilities’ impact in their IT environments, in order to stay as safe as possible.
“It’s not a simple [process] of just install a patch and you’re done,” he said.
## A different animal
Graham outlined a num
Fortinet
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
blogs_fortinet·2018-01-12
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
FORTIGUARD LABS THREAT RESEARCH
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
By Minh Tran | January 12, 2018
Introduction
2018 truly is starting off with a bang: fundamental CPU flaws dubbed Meltdown and Spectre were found affecting pretty much all modern processors developed since the Pentium Pro (1995). These flaws root in two critical CPU features: Out of Order Execution and Speculative Execution, which are crucial for performance. Since this is an important feature and not a bug, it is inherently hard to fix. Furthermore, for performance reasons, speculative execution is almost always implemented in hardware, so “fixes” tend toward mitigations (e.g. microcode updates).
Due to the serious nature of these flaws,
Qualys
Meltdown/Spectre and Qualys Cloud Platform | Qualys
blogs_qualys·2018-01-09·CVSS 5.6
[MEDIUM] Meltdown/Spectre and Qualys Cloud Platform | Qualys
In light of the recently released information about two security vulnerabilities, Qualys has considered the impact on the Qualys Cloud Platform and associated services. Qualys released a detailed advisory for customers of the Qualys Cloud Platform to help customers identify these vulnerabilities and to assist customers in their internal security assessment.
Below, please find information about how Qualys has performed its assessment and is taking steps to protect its environment and the Qualys Cloud Platform:
### About Meltdown and Spectre
Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5715 and CVE-2017-5753) exploit physical implementations of modern microprocessors, rather than relying on any software-based flaw or defect.
### Impact
As of this writing, there is no known exploit for
Qualys
Meltdown/Spectre and Qualys Cloud Platform
blogs_qualys·2018-01-09·CVSS 5.6
[MEDIUM] Meltdown/Spectre and Qualys Cloud Platform
In light of the recently released information about two security vulnerabilities, Qualys has considered the impact on the Qualys Cloud Platform and associated services. Qualys released a detailed advisory for customers of the Qualys Cloud Platform to help customers identify these vulnerabilities and to assist customers in their internal security assessment.
Below, please find information about how Qualys has performed its assessment and is taking steps to protect its environment and the Qualys Cloud Platform:
## About Meltdown and Spectre
Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5715 and CVE-2017-5753) exploit physical implementations of modern microprocessors, rather than relying on any software-based flaw or defect.
## Impact
As of this writing, there is no known exploit for t
Qualys
January 2018 Patch Tuesday - Meltdown/Spectre, 16 Critical Microsoft Patches, 1 Adobe Patch | Qualys
blogs_qualys·2018-01-09·CVSS 5.6
[MEDIUM] January 2018 Patch Tuesday - Meltdown/Spectre, 16 Critical Microsoft Patches, 1 Adobe Patch | Qualys
Due to the disclosure of Meltdown and Spectre, Microsoft released several patches last week with the ranking “Important.” While there are no active attacks against these vulnerabilities, a special focus should be placed on any of the browser patches, due to potential attacks using JavaScript.
It is important to note that OS-level and BIOS (microcode) patches that are designed to mitigate Meltdown and Spectre may lead to performance issues. It is important to test all patches before deploying.
Some of these updates are incompatible with third-party antivirus software, and may require updating AV on workstations and servers. Microsoft has released guidance documents for both Windows clients and servers. Windows Server requires registry changes in order to implement the protections added by
Qualys
January 2018 Patch Tuesday – Meltdown/Spectre, 16 Critical Microsoft Patches, 1 Adobe Patch
blogs_qualys·2018-01-09·CVSS 5.6
[MEDIUM] January 2018 Patch Tuesday – Meltdown/Spectre, 16 Critical Microsoft Patches, 1 Adobe Patch
Due to the disclosure of Meltdown and Spectre , Microsoft released several patches last week with the ranking “Important.” While there are no active attacks against these vulnerabilities, a special focus should be placed on any of the browser patches, due to potential attacks using JavaScript.
It is important to note that OS-level and BIOS (microcode) patches that are designed to mitigate Meltdown and Spectre may lead to performance issues. It is important to test all patches before deploying.
Some of these updates are incompatible with third-party antivirus software, and may require updating AV on workstations and servers. Microsoft has released guidance documents for both Windows clients and servers . Windows Server requires registry changes in order to implement the protections added
Talos
Meltdown and Spectre
blogs_talos·2018-01-08·CVSS 5.6
[MEDIUM] Meltdown and Spectre
## Meltdown and Spectre
Cisco Talos is aware of three new vulnerabilities impacting Intel, AMD, Qualcomm and ARM processors used by almost all computers. We are investigating these issues and although we have not observed exploitation of these vulnerabilities in the wild, that does not mean that it has not occurred. We have observed publicly available proof of concept exploit code being developed to exploit these vulnerabilities.
These issues have been assigned the following CVE entries:
Meltdown: An attacker can access kernel memory from user space
Rogue data cache load ( CVE-2017-5754 ) Spectre: An attacker can read memory contents from other users' running programs
Branch target injection ( CVE-2017-5715 )
Bounds check bypass ( CVE-2017-5753 ) These issues involve side channel and
Talos
Meltdown and Spectre
blogs_talos·2018-01-08·CVSS 5.6
[MEDIUM] Meltdown and Spectre
Cisco Talos is aware of three new vulnerabilities impacting Intel, AMD, Qualcomm and ARM processors used by almost all computers. We are investigating these issues and although we have not observed exploitation of these vulnerabilities in the wild, that does not mean that it has not occurred. We have observed publicly available proof of concept exploit code being developed to exploit these vulnerabilities.
These issues have been assigned the following CVE entries:
Meltdown: An attacker can access kernel memory from user space
- Rogue data cache load (CVE-2017-5754) Spectre: An attacker can read memory contents from other users' running programs
- Branch target injection (CVE-2017-5715)
- Bounds check bypass (CVE-2017-5753)
These issues involve side channel and cache attacks that enable
Trendmicro
Understanding Meltdown and Spectre
blogs_trendmicro·2018-01-05
Understanding Meltdown and Spectre
Exploits & Vulnerabilities
# Understanding Meltdown and Spectre
After the official disclosure of the Meltdown and Spectre vulnerabilities, it became clear how serious the problems were. In short, Meltdown and Spectre both allow malicious code to read memory that they would normally not have permission to.
By: Vit Sembera
2018/01/05
Read time: ( words)
Save to Folio
For several days, rumors circulated about a serious vulnerability in Intel processors. It wasn’t until January 3 that the official disclosure of the Meltdown and Spectre vulnerabilities was made, and it became clear how serious the problems were. To summarize, Meltdown and Spectre both allow malicious code to read memory that they would normally not have permission to.
The vulnerability can allow an attacker to steal info
Zscaler
Meltdown, Spectre, CPU Side-Channel Attack | Zscaler Blog
blogs_zscaler·2018-01-05
Meltdown, Spectre, CPU Side-Channel Attack | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
blogs_tenable·2018-01-04
The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Processor Vulnerabilities – Meltdown and Spectre
blogs_qualys·2018-01-04·CVSS 5.6
CVE-2017-5754 [MEDIUM] Processor Vulnerabilities – Meltdown and Spectre
UPDATE 1/4/2018: Qualys has released several QIDs for detecting missing patches for these vulnerabilities.
UPDATE 1/5/2018: Pre-built AssetView dashboards to visualize impact and remediation progress.
Vulnerabilities potentially impacting all major processor vendors were disclosed today by Google Project Zero. These vulnerabilities have been named Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753 & CVE-2017-5715). Organizations should inventory their systems by processor type, apply vendor patches as they become available, and track their progress. This article describes how Qualys can help in all three areas.
## Overview
Meltdown allows any application to access all system memory, including memory allocated for the kernel. Mitigation for this vulnerability will require operating syst
Sentinelone
SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes
blogs_sentinelone·2018-01-04·CVSS 5.6
CVE-2017-5753 [MEDIUM] SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes
This document covers SentinelOne’s response to exploit flaws described in CVE-2017-5753, CVE-2017-5715, and CVE-2017-5754.
SentinelOne products are compatible with Microsoft’s January 3, 2018, security updates. We tested our Agent against Microsoft’s patch. No incompatibilities causing any stop errors or other issues were found with SentinelOne agent versions 1.8.4, 2.0, 2.1 and 2.5.
## Overview
Microsoft, Google, Linux RedHat and Amazon have all acknowledged a new, publicly disclosed class of vulnerabilities referred to as “speculative execution side-channel attacks,” which affect many modern processors and operating systems including Intel, AMD, and ARM. This issue may also affect other systems, such as Android, Chrome, iOS, MacOS.
## Possible collision with security applications
Mi
Sentinelone
SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes
blogs_sentinelone·2018-01-04·CVSS 5.6
CVE-2017-5753 [MEDIUM] SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes
This document covers SentinelOne’s response to exploit flaws described in CVE-2017-5753 , CVE-2017-5715 , and CVE-2017-5754 .
SentinelOne products are compatible with Microsoft’s January 3, 2018, security updates. We tested our Agent against Microsoft’s patch. No incompatibilities causing any stop errors or other issues were found with SentinelOne agent versions 1.8.4, 2.0, 2.1 and 2.5.
## Overview
Microsoft , Google , Linux RedHat and Amazon have all acknowledged a new, publicly disclosed class of vulnerabilities referred to as “speculative execution side-channel attacks,” which affect many modern processors and operating systems including Intel, AMD, and ARM. This issue may also affect other systems, such as Android, Chrome, iOS, MacOS.
## Possible collision with security application
Unit42
Threat Brief: Meltdown and Spectre Vulnerabilities
blogs_unit42·2018-01-04·CVSS 5.6
[MEDIUM] Threat Brief: Meltdown and Spectre Vulnerabilities
Bottom line up front:
- The Meltdown and Spectre vulnerabilities are serious vulnerabilities
- These vulnerabilities are uniquely broad in scope potentially affecting nearly every computer and device with a modern processor: Microsoft Windows, Google Android, Google ChromeOS, Apple macOS, on Intel and ARM processors.
- These are not code execution vulnerabilities (i.e. wormable): they are information disclosure vulnerabilities
- These vulnerabilities pose greatest risk in shared hosting scenarios (i.e. cloud)
- The risk these vulnerabilities pose for end users is that malicious code or script could use them to obtain sensitive information like usernames, passwords, and bank account information
- Because of the breadth of these vulnerabilities, IoT devices and many mobile devices may never
Tenable
The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
blogs_tenable·2018-01-04
The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
Blog / Research
Subscribe
# The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
Cody Dumont
January 4, 2018
6 Min Read
This post was updated on Jan. 12, 2018 to include additional technical details and supplemental links.
The recently disclosed Meltdown and Spectre vulnerabilities started off 2018 with a somber note, as the attacks affect everything from desktops, laptops and mobile devices to cloud providers’ infrastructure. The flaws are present in nearly all modern microprocessors and can allow an attacker to access privileged memory by abusing a feature called speculative execution.
### Speculative execution
Speculative execution is a technique that allows a microprocessor to increase performance by operating on multiple branches of instructions at once
Unit42
Threat Brief: Meltdown and Spectre Vulnerabilities
blogs_unit42·2018-01-04
Threat Brief: Meltdown and Spectre Vulnerabilities
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Meltdown and Spectre Vulnerabilities
Unit 42
Published: January 4, 2018
High Profile Threats
Vulnerabilities
AMD
Android
ARM
Intel
Linux
MacOS
Microsoft Windows
Bottom line up front:
The Meltdown and Spectre vulnerabilities are serious vulnerabilities
These vulnerabilities are uniquely broad in scope potentially affecting nearly every computer and device with a modern processor: Microsoft Windows, Google Android, Google ChromeOS, Apple macOS, on Intel and ARM processors.
These are not code execution vulnerabilities (i.e. wormable): they are information disclosure vulnerabilities
These vulnerabilities pose greatest risk in shared hosting scenarios (i.e. cloud)
The risk these vulnerabilities po
Fortinet
Fortinet Advisory on New Spectre and Meltdown Vulnerabilities
blogs_fortinet·2018-01-04·CVSS 5.6
[MEDIUM] Fortinet Advisory on New Spectre and Meltdown Vulnerabilities
FORTINET NEWS & UPDATES
Fortinet Advisory on New Spectre and Meltdown Vulnerabilities
By Fortinet | January 04, 2018
Earlier this week, it was announced that researchers uncovered two new side channel attacks that exploit newly discovered vulnerabilities found in most CPU processors, including those from Intel, AMD, and ARM. These vulnerabilities allow malicious userspace processes to read kernel memory, thereby potentially causing sensitive kernel information to leak. These vulnerabilities are known as Meltdown and Spectre.
Fortinet’s PSIRT team is actively conducting an extensive review to determine the potential impact to Fortinet solutions, and at this time has classified the risk to Fortinet products as low. Meltdown and Spectre are "Information Disclosure" and "Privilege Escalatio
Qualys
Processor Vulnerabilities - Meltdown and Spectre | Qualys
blogs_qualys·2018-01-04·CVSS 5.6
CVE-2017-5754 [MEDIUM] Processor Vulnerabilities - Meltdown and Spectre | Qualys
UPDATE 1/4/2018: Qualys has released several QIDs for detecting missing patches for these vulnerabilities.
UPDATE 1/5/2018: Pre-built AssetView dashboards to visualize impact and remediation progress.
Vulnerabilities potentially impacting all major processor vendors were disclosed today by Google Project Zero. These vulnerabilities have been named Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753 & CVE-2017-5715). Organizations should inventory their systems by processor type, apply vendor patches as they become available, and track their progress. This article describes how Qualys can help in all three areas.
### Overview
Meltdown allows any application to access all system memory, including memory allocated for the kernel. Mitigation for this vulnerability will require operating sy
Tenable
Spectre & Meltdown
blogs_tenable·2018-01-04
Spectre & Meltdown
by Steve Tilson January 4, 2018
A compromised processor is one of the most serious attack vectors on all Microsoft, Apple, and Linux systems. The recent discovered hardware bugs known as “Spectre & Meltdown” affect modern processors uniquely by accessing information found in the system’s memory. This Dashboard can provide insight to which systems are prone to the new vulnerability.
The new bugs are considered side channel attacks since they use side channels to obtain the information from the accessed memory location. Spectre allows an application to force another application to access arbitrary portions of its memory, which can then be read through a side channel. This unique side channel attack is done by speculative execution, a technique used by high-speed processors in order to incr
Huntress
CVE-2017-5715 Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715 Vulnerability: Analysis, Impact, Mitigation | Huntress
CVE-2017-5715 Vulnerability
Published: 2/20/2025
Written by: Lizzie Danielson
## What is CVE-2017-5715 vulnerability?
CVE-2017-5715, commonly referred to as "Spectre Variant 2," is a hardware vulnerability stemming from speculative execution—a feature in CPUs designed to improve performance by predicting future instructions. This vulnerability can lead to information leakage by exploiting branch target injection, allowing attackers to access privileged memory in impacted systems. CVE-2017-5715 is classified as a speculative execution side-channel vulnerability and has significant implications for data confidentiality and system integrity.
## When was it discovered?
CVE-2017-5715 was publicly disclosed in January 2018 by a collaborative effort involving researchers from Google Project
Sentinelone
Black Basta
blogs_sentinelone
Black Basta
# Black Basta Ransomware: In-Depth Analysis, Detection, and Mitigation
## Summary of Black Basta Ransomware
Black Basta first emerged in early 2022. The ransomware family is an evolution of the Hermes/Ryuk/Conti families. Black Basta was heavily advertised in underground cybercrime markets. Black Basta practices double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. There are Windows and LInux variants of Black Basta ransomware. The group is responsible for hundreds of attacks against global targets of varying sectors.
February 2025 Update: Nearly a year’s worth of Black Basta chat logs have been released on Telegram, providing detailed insight into the groups operational workflow, reconnaissance activities, and specific userID and details o
Crowdstrike
What are the Spectre & Meltdown Chip Flaws?
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] What are the Spectre & Meltdown Chip Flaws?
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
arxiv_fulltext·2024-06-09
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
Aidan Z.H. Yang
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Haoye Tian
[email protected]
University of Melbourne
Melbourne
Australia
He Ye
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Ruben Martins
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Claire Le Goues
[email protected]
Carnegie Mellon University
Pittsburgh
United States
## Abstract
Software security vulnerabilities allow attackers to perform malicious activities to disrupt software operations. Recent Transformer-based language models have significantly advanced vulnerability detection, surpassing the capabilities of static analysis based deep lear
arXiv
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
arxiv_fulltext·2023-08-23
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
M. Mehdi Kholoosi12,
M. Ali Babar12,
Cemal Yilmaz3
1 School of Computer Science, CREST, The University of Adelaide, Adelaide, Australia
2 Cyber Security Cooperative Research Centre, Australia
3 Faculty of Engineering and Natural Sciences, Sabanci University, Istanbul, 34956, Turkey
Emails: [email protected], [email protected], [email protected]
## Abstract
Timing attacks are considered one of the most damaging side-channel attacks. These attacks exploit timing fluctuations caused by certain operations to disclose confidential information to an attacker. For instance, in asymmetric encryption, operations such as multiplication and division can cause time-varying execution times th
arXiv
SafeBet: Secure, Simple, and Fast Speculative Execution
arxiv_fulltext·2023-06-13
SafeBet: Secure, Simple, and Fast Speculative Execution
empty
plain
## Abstract
Spectre attacks exploit microprocessor speculative execution to read and transmit forbidden data outside the attacker's trust domain and sandbox.
Recent hardware schemes allow potentially-unsafe speculative accesses but prevent the secret's transmission by delaying all or many of the access-dependent instructions even in the predominantly-common, no-attack case, which incurs performance loss and hardware complexity.
Instead, we propose which allows only, and in the common case does not delay most, safe accesses. We first consider the simple case
without (i) code control flow transfer across trust domains or (ii) data memory sandbox boundary changes (i.e., some locations dynamically move across sandboxes);
and then extend to the complex cases with these behaviors.
Bugzilla
CVE-2022-23824 hw: cpu: AMD: IBPB and Return Address Predictor Interactions
bugzilla·2022-08-17·CVSS 5.6
CVE-2022-23824 [MEDIUM] CVE-2022-23824 hw: cpu: AMD: IBPB and Return Address Predictor Interactions
CVE-2022-23824 hw: cpu: AMD: IBPB and Return Address Predictor Interactions
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
This issue (CVE-2022-23824 or AMD-SN-1040) related to CVE-2017-5715 previously known as Spectre Variant 2. As part of our efforts to continue improving security features, AMD has investigated issues related to CVE-2017-5715 in the recent months. Previously notified of one of the potential issues related to CVE-2017-5715 (in AMD-SN-1036). In some situations, IBPB may fail to prevent return branch predictions from being specified by pre-IBPB branch targets leading to potential information disclosure.
Reference:
https://www.amd.com/en/corporate/product-security/bulletin/amd-s
Bugzilla
CVE-2017-5715 arm-trusted-firmware: hw: cpu: speculative execution branch target injection [fedora-all]
bugzilla·2018-01-08·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715 arm-trusted-firmware: hw: cpu: speculative execution branch target injection [fedora-all]
CVE-2017-5715 arm-trusted-firmware: hw: cpu: speculative execution branch target injection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2017-5715 kernel: hw: cpu: speculative execution branch target injection [fedora-all]
bugzilla·2018-01-03·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715 kernel: hw: cpu: speculative execution branch target injection [fedora-all]
CVE-2017-5715 kernel: hw: cpu: speculative execution branch target injection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2017-5715 hw: cpu: speculative execution branch target injection
bugzilla·2017-12-01·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715 hw: cpu: speculative execution branch target injection
CVE-2017-5715 hw: cpu: speculative execution branch target injection
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited.
Variant CVE-2017-5715 triggers the speculative execution by utilizing branch target injection. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to cross t
CWE
Processor Optimization Removal or Modification of Security-critical Code
mitre_cwe·CVSS 5.6
[MEDIUM] CWE-1037 Processor Optimization Removal or Modification of Security-critical Code
CWE-1037: Processor Optimization Removal or Modification of Security-critical Code
The developer builds a security-critical protection mechanism into the software, but the processor optimizes the execution of the program such that the mechanism is removed or modified.
Modes of Introduction:
Phase: Architecture and Design
Note: Optimizations built into the design of the processor can have unintended consequences during the execution of an application.
Common Consequences:
Scope: Integrity. Impact: Bypass Protection Mechanism. A successful exploitation of this weakness will change the order of an application's execution and will likely be used to bypass specific protection mechanisms. This bypass can be exploited further to potentially read data that should otherwise be unaccessible.
Det
CWE
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
mitre_cwe
CWE-1421 Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
CWE-1421: Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
A processor event may allow transient operations to access
architecturally restricted data (for example, in another address
space) in a shared microarchitectural structure (for example, a CPU
cache), potentially exposing the data over a covert channel.
Many commodity processors have Instruction Set Architecture (ISA)
features that protect software components from one another. These
features can include memory segmentation, virtual memory, privilege
rings, trusted execution environments, and virtual machines, among
others. For example, virtual memory provides each process with its own
address space, which prevents processes from accessing each other's
private data. Many of these
CWE
Insecure Automated Optimizations
mitre_cwe
CWE-1038 Insecure Automated Optimizations
CWE-1038: Insecure Automated Optimizations
The product uses a mechanism that automatically optimizes code, e.g. to improve a characteristic such as performance, but the optimizations can have an unintended side effect that might violate an intended security assumption.
Modes of Introduction:
Phase: Architecture and Design
Note: Optimizations built into the design of a product can have unintended consequences during execution.
Common Consequences:
Scope: Integrity. Impact: Alter Execution Logic. The optimizations alter the order of execution resulting in side effects that were not intended by the original developer.
Examples:
The following code reads a password from the
user, uses the password to connect to a back-end
mainframe, and then attempts to scrub the password from
memory using
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4609http://nvidia.custhelp.com/app/answers/detail/a_id/4611http://nvidia.custhelp.com/app/answers/detail/a_id/4613http://nvidia.custhelp.com/app/answers/detail/a_id/4614http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.htmlhttp://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txthttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txthttp://www.kb.cert.org/vuls/id/584653http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/102376http://www.securitytracker.com/id/1040071http://xenbits.xen.org/xsa/advisory-254.htmlhttps://access.redhat.com/errata/RHSA-2018:0292https://access.redhat.com/security/vulnerabilities/speculativeexecutionhttps://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://cert.vde.com/en-us/advisories/vde-2018-002https://cert.vde.com/en-us/advisories/vde-2018-003https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityhttps://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.htmlhttps://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixeshttps://lists.debian.org/debian-lts-announce/2018/05/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2021/08/msg00019.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002https://seclists.org/bugtraq/2019/Jun/36https://seclists.org/bugtraq/2019/Nov/16https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-frhttps://security.FreeBSD.org/advisories/FreeBSD-SA-18:03.speculative_execution.aschttps://security.FreeBSD.org/advisories/FreeBSD-SA-19:26.mcu.aschttps://security.gentoo.org/glsa/201810-06https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.htmlhttps://security.netapp.com/advisory/ntap-20180104-0001/https://security.paloaltonetworks.com/CVE-2017-5715https://spectreattack.com/https://support.citrix.com/article/CTX231399https://support.f5.com/csp/article/K91229003https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_ushttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_ushttps://support.lenovo.com/us/en/solutions/LEN-18282https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannelhttps://usn.ubuntu.com/3531-1/https://usn.ubuntu.com/3531-3/https://usn.ubuntu.com/3540-2/https://usn.ubuntu.com/3541-2/https://usn.ubuntu.com/3542-2/https://usn.ubuntu.com/3549-1/https://usn.ubuntu.com/3560-1/https://usn.ubuntu.com/3561-1/https://usn.ubuntu.com/3580-1/https://usn.ubuntu.com/3581-1/https://usn.ubuntu.com/3581-2/https://usn.ubuntu.com/3582-1/https://usn.ubuntu.com/3582-2/https://usn.ubuntu.com/3594-1/https://usn.ubuntu.com/3597-1/https://usn.ubuntu.com/3597-2/https://usn.ubuntu.com/3620-2/https://usn.ubuntu.com/3690-1/https://usn.ubuntu.com/3777-3/https://usn.ubuntu.com/usn/usn-3516-1/https://www.debian.org/security/2018/dsa-4120https://www.debian.org/security/2018/dsa-4187https://www.debian.org/security/2018/dsa-4188https://www.debian.org/security/2018/dsa-4213https://www.exploit-db.com/exploits/43427/https://www.kb.cert.org/vuls/id/180049https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/https://www.synology.com/support/security/Synology_SA_18_01https://www.vmware.com/security/advisories/VMSA-2018-0007.htmlhttps://www.vmware.com/us/security/advisories/VMSA-2018-0002.htmlhttps://www.vmware.com/us/security/advisories/VMSA-2018-0004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
+ 88 more references
2018-01-04
Published