CVE-2018-12130 — Sensitive Information Exposure in Intel-microcode
CWE-200 — Sensitive Information ExposureCWE-208 — Observable Timing Discrepancy61 documents17 sources
Severity
5.6MEDIUMNVD
EPSS
0.5%
top 32.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 30
Latest updateFeb 24
Description
Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
CVSS vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 1.1 | Impact: 4.0
Affected Packages12 packages
▶CVEListV5intel_corporation/central_processing_unitsA list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
Also affects: Fedora 29
🔴Vulnerability Details
15GHSA▶
GHSA-j579-gjpv-mwhp: Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated↗2022-05-24
OSV▶
CVE-2018-12130: Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated↗2019-05-30
📋Vendor Advisories
23🕵️Threat Intelligence
14Tenable▶
Objects in Mirror Are Closer Than They Appear: Reflecting on the Cybersecurity Threats from 2019↗2019-12-16
📄Research Papers
1💬Community
7Bugzilla▶
CVE-2018-12130 kernel: hardware: Microarchitectural Fill Buffer Data Sampling (MFBDS) [fedora-all]↗2019-05-14
Bugzilla▶
CVE-2018-12130 libvirt: hardware: Microarchitectural Fill Buffer Data Sampling (MFBDS) [fedora-all]↗2019-05-14
Bugzilla▶
CVE-2018-12130 qemu: hardware: Microarchitectural Fill Buffer Data Sampling (MFBDS) [fedora-all]↗2019-05-14
Bugzilla▶
CVE-2018-12130 kernel: hardware: Microarchitectural Fill Buffer Data Sampling (MFBDS) [fedora-all]↗2019-05-14
Bugzilla▶
CVE-2018-12130 libvirt: hardware: Microarchitectural Fill Buffer Data Sampling (MFBDS) [fedora-all]↗2019-05-14