Severity
5.6MEDIUM
EPSS
87.6%
top 0.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 4
Latest updateSep 1

Description

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 1.1 | Impact: 4.0

Affected Packages32 packages

Debianxen< 4.11.1~pre+1.733450b39b-1+3
Debianlinux< 4.14.12-1+3
Ubuntulinux< 4.4.0-109.132
Ubuntufirefox< 57.0.4+build1-0ubuntu0.14.04.1+1

Patches

🔴Vulnerability Details

9
OSV
linux-hwe vulnerabilities2018-03-15
Kernel
arm64: Turn on KPTI only on CPUs that need it2018-01-19
Kernel
KVM: PPC: Book3S: Provide information about hardware/firmware CVE workarounds2018-01-15
OSV
linux regression2018-01-10
OSV
linux-lts-xenial regression2018-01-10

💥Exploits & PoCs

1
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities2018-06-12

🔍Detection Rules

1
Suricata
ET EXPLOIT Possible MeltDown PoC Download In Progress2018-01-10

📋Vendor Advisories

27
Android
CVE-2017-5754: Kernel Memory2018-09-01
Red Hat
xen: x86 PV guest may crash Xen with XPTI2018-04-25
Ubuntu
Linux kernel vulnerabilities2018-03-15
Ubuntu
Linux kernel (HWE) vulnerabilities2018-03-15
BSD
FreeBSD-SA-18:03.speculative_execution: Speculative Execution Vulnerabilities2018-03-14

🕵️Threat Intelligence

5
Fortinet
Meltdown/Spectre Update2018-01-30
Qualys
Processor Vulnerabilities – Meltdown and Spectre2018-01-04
Sentinelone
SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes2018-01-04
Sentinelone
SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes2018-01-04
Qualys
Processor Vulnerabilities - Meltdown and Spectre | Qualys2018-01-04

💬Community

3
Bugzilla
firefox: mitigations against spectre via javascript2018-01-08
Bugzilla
CVE-2017-5754 kernel: hw: cpu: speculative execution permission faults handling [fedora-all]2018-01-03
Bugzilla
CVE-2017-5754 hw: cpu: speculative execution permission faults handling2017-12-01
CVE-2017-5754 (MEDIUM CVSS 5.6) | Systems with microprocessors utiliz | cvebase.io