cbcvebase.
CVE-2018-15572
published 2018-08-20

CVE-2018-15572: The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context switch, which…

PriorityP425medium6.5CVSS 3.0
AVLACLPRLUINSCCHINAN
EPSS
0.51%
40.8th percentile
The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context switch, which makes it easier for attackers to conduct userspace-userspace spectreRSB attacks.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.17.15-1 (bookworm)linux 4.17.15-1 (bookworm)
linuxlinux_kernel< 4.18.14.18.1
linuxlinux_kernel>= 0 < 4.17.15-14.17.15-1
linuxlinux_kernel>= 0 < 4.17.15-14.17.15-1
linuxlinux_kernel>= 0 < 4.17.15-14.17.15-1
linuxlinux_kernel>= 0 < 4.17.15-14.17.15-1
linuxlinux_kernel>= 0 < 3.13.0-160.2103.13.0-160.210
linuxlinux_kernel>= 0 < 4.4.0-137.1634.4.0-137.163
linuxlinux_kernel>= 0 < 4.15.0-36.394.15.0-36.39

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.0HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.