CVE-2018-3640
published 2018-05-22CVE-2018-3640: Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system…
PriorityP432medium5.6CVSS 3.0
AVLACHPRLUINSCCHINAN
EPSS
7.56%
93.8th percentile
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
Affected
323 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_mojave_10.14.1_security_update_2018-002_high_sierra_security_update_2018-0 | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| debian | intel-microcode | < intel-microcode 3.20180703.1 (bookworm) | intel-microcode 3.20180703.1 (bookworm) |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_e | — | — |
| intel | atom_e | — | — |
| intel | atom_e | — | — |
| intel | atom_e | — | — |
CVSS provenance
nvdv3.05.6MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
vendor_cisco5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-3640: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
vendor_apple·2018-10-30·CVSS 5.6
CVE-2018-3640 [MEDIUM] CVE-2018-3640: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
Product: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
CVE: CVE-2018-3640
Component: Microcode
Impact: Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis
Description: An information disclosure issue was addressed with a microcode update. This ensures that implementation specific system registers cannot be leaked via a speculative execution side-channel.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2018-08-27·CVSS 5.5
CVE-2018-3639 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: The system could be made to expose sensitive information.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
Jann Horn and Ken Johnson discovered that microprocessors utilizing
speculative execution of a memory read may allow unauthorized memory reads
via a sidechannel attack. This flaw is known as Spectre Variant 4. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2018-3639)
Zdenek So
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: May 2018
vendor_cisco·2018-05-22·CVSS 5.5
CVE-2018-3639 [MEDIUM] CPU Side-Channel Information Disclosure Vulnerabilities: May 2018
CPU Side-Channel Information Disclosure Vulnerabilities: May 2018
On May 21, 2018, researchers disclosed two vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes.
The first vulnerability, CVE-2018-3639, is known as Spectre Variant 4 or SpectreNG. The second vulnerability, CVE-2018-3640, is known as Spectre Variant 3a. Both of these attacks are variants of the attacks disclosed in January 2018 and leverage cache-timing attacks to infer any disclosed data.
To exploit either of these vulnerabilities, a
Red Hat
hw: cpu: speculative register load
vendor_redhat·2018-05-21·CVSS 5.6
CVE-2018-3640 [MEDIUM] CWE-1231 hw: cpu: speculative register load
hw: cpu: speculative register load
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
An industry-wide issue was found in the way many modern microprocessor handle speculative access of system registers inaccessible to unprivileged user. It relies on the presence of a precisely-defined instruction sequence in the privileged code which allows speculative load of system registers and that such register value could be subsequently used in speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use
Debian
CVE-2018-3640: intel-microcode - Systems with microprocessors utilizing speculative execution and that perform sp...
vendor_debian·2018·CVSS 5.6
CVE-2018-3640 [MEDIUM] CVE-2018-3640: intel-microcode - Systems with microprocessors utilizing speculative execution and that perform sp...
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
Scope: local
bookworm: resolved (fixed in 3.20180703.1)
bullseye: resolved (fixed in 3.20180703.1)
forky: resolved (fixed in 3.20180703.1)
sid: resolved (fixed in 3.20180703.1)
trixie: resolved (fixed in 3.20180703.1)
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: May 2018
vendor_cisco
CVE-2018-3640 CPU Side-Channel Information Disclosure Vulnerabilities: May 2018
CVE-2018-3640: CPU Side-Channel Information Disclosure Vulnerabilities: May 2018
On May 21, 2018, researchers disclosed two vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes. The first vulnerability, CVE-2018-3639, is known as Spectre Variant 4 or SpectreNG . The second vulnerability, CVE-2018-3640, is known as Spectre Variant 3a . Both of these attacks are variants of the attacks disclosed in January 2018 and leverage cache-timing attacks to infer any disclosed data. To exploit either of these vu
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: May 2018
vendor_cisco
CVE-2018-3639 CPU Side-Channel Information Disclosure Vulnerabilities: May 2018
CVE-2018-3639: CPU Side-Channel Information Disclosure Vulnerabilities: May 2018
On May 21, 2018, researchers disclosed two vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes. The first vulnerability, CVE-2018-3639, is known as Spectre Variant 4 or SpectreNG . The second vulnerability, CVE-2018-3640, is known as Spectre Variant 3a . Both of these attacks are variants of the attacks disclosed in January 2018 and leverage cache-timing attacks to infer any disclosed data. To exploit either of these vu
GHSA
GHSA-wm4v-x65g-m25r: Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure
ghsa_unreviewed·2022-05-13
CVE-2018-3640 [MEDIUM] CWE-203 GHSA-wm4v-x65g-m25r: Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
OSV
intel-microcode vulnerabilities
osv·2018-08-27·CVSS 5.5
CVE-2018-3646 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
Jann Horn and Ken Johnson discovered that microprocessors utilizing
speculative execution of a memory read may allow unauthorized memory reads
via a sidechannel attack. This flaw is known as Spectre Variant 4. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2018-3639)
Zdenek Sojka, Rudolf Marek, Alex Zuepke, and Innokentiy Sennovskiy
discovered that m
OSV
CVE-2018-3640: Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure
osv·2018-05-22·CVSS 5.6
CVE-2018-3640 [MEDIUM] CVE-2018-3640: Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
No detection rules found.
No public exploits indexed.
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15·CVSS 5.6
[MEDIUM] 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Blog / Research
Subscribe
# 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Pablo Ramos
November 15, 2018
5 Min Read
The classes of vulnerabilities that brought us Meltdown and Spectre are not going away anytime soon. Here’s what you need to know about Speculative Execution vulnerabilities, with our guidance on steps you can take to reduce your risk.
Spectre and Meltdown generated a lot of confusion and discussion in the security world when they first hit the news. Understanding the risks associated with speculative execution vulnerabilities will help organizations prioritize and communicate effectively about their exposure. In this post, we present what it is known, how it affects companies and ways to stay ahead in the game.
## Start from the beginning…
Speculative Ex
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15
5W1H: Speculative Side Channel Vulnerabilities De-mystified
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
All Hands Memo to Owners of Home / Small Office Routers: Reboot Them! | Qualys
blogs_qualys·2018-05-30
All Hands Memo to Owners of Home / Small Office Routers: Reboot Them! | Qualys
This last week or so of May has been busy with security news and incidents, as the FBI put out an unprecedented call to do a massive wave of reboots of home and small office routers, while Intel confirmed the existence of yet another Spectre / Meltdown variant. And, yes, we had yet another high-profile instance of an unprotected AWS storage bucket exposing data, as well as more IoT security bad news.
### Unplug and reset that router pronto!
As you may have heard by now, THE FBI WANTS YOU TO REBOOT YOUR ROUTERS!
Sorry, we didn’t mean to use our outside voice and startle you, but the urgent and extraordinary plea from the feds has been ubiquitous in recent days and we wouldn’t want you to be out of the loop.
The reason: It takes a village to dismantle a botnet that has infected 500,000 h
Qualys
All Hands Memo to Owners of Home / Small Office Routers: Reboot Them!
blogs_qualys·2018-05-30
All Hands Memo to Owners of Home / Small Office Routers: Reboot Them!
This last week or so of May has been busy with security news and incidents, as the FBI put out an unprecedented call to do a massive wave of reboots of home and small office routers, while Intel confirmed the existence of yet another Spectre / Meltdown variant. And, yes, we had yet another high-profile instance of an unprotected AWS storage bucket exposing data, as well as more IoT security bad news.
## Unplug and reset that router pronto!
As you may have heard by now, THE FBI WANTS YOU TO REBOOT YOUR ROUTERS!
Sorry, we didn’t mean to use our outside voice and startle you, but the urgent and extraordinary plea from the feds has been ubiquitous in recent days and we wouldn’t want you to be out of the loop.
The reason: It takes a village to dismantle a botnet that has infected 500,000 ho
Tenable
Spectre And Meltdown Still Haunting Intel/AMD
blogs_tenable·2018-05-22
Spectre And Meltdown Still Haunting Intel/AMD
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Spectre And Meltdown Still Haunting Intel/AMD
blogs_tenable·2018-05-22·CVSS 5.5
[MEDIUM] Spectre And Meltdown Still Haunting Intel/AMD
Blog / Research
Subscribe
# Spectre And Meltdown Still Haunting Intel/AMD
Steve Tilson
May 22, 2018
4 Min Read
The ongoing saga of the Spectre and Meltdown vulnerabilities has just taken a new turn. Discovered by Google Project Zero (GPZ) and Microsoft, the new variants affect everything from desktops, laptops and mobile devices to infrastructure-as-a-service. These flaws are present in nearly all modern microprocessors and could allow an attacker to steal sensitive information by accessing privileged memory as a result of abusing a feature called speculative execution. We’ve been following the ongoing developments of these vulnerabilities from their first disclosure back in January 2018 and have released coverage to help keep our customers secure based on previous developments. The v
Bugzilla
CVE-2018-3640 hw: cpu: speculative register load
bugzilla·2018-05-21·CVSS 5.6
CVE-2018-3640 [MEDIUM] CVE-2018-3640 hw: cpu: speculative register load
CVE-2018-3640 hw: cpu: speculative register load
An industry-wide issue was found in the way many modern microprocessor handle
speculative access of system registers inaccessible to unprivileged user.
It relies on the presence of a precisely-defined instruction sequence in the
privileged code which allows speculative load of system registers and that such
register value could be subsequently used in speculatively executed instructions that never actually commit (retire).
As a result, an unprivileged attacker could use this flaw to read privileged
system registers by conducting targeted cache side-channel attacks.
Reference:
-> https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
Discussion:
External References:
https://access.redhat.com/solution
arXiv
Reviving Meltdown 3a
arxiv_fulltext·2023-10-06
Reviving Meltdown 3a
Reviving Meltdown 3a
Daniel Weber
Fabian Thomas
Lukas Gerlach
Ruiyi Zhang
Michael Schwarz
Weber et al.
CISPA Helmholtz Center for Information Security
Saarbr\"ucken, Saarland, Germany
[email protected]
## Abstract
Since the initial discovery of Meltdown and Spectre in 2017, different variants of these attacks have been discovered.
One often overlooked variant is Meltdown 3a, also known as .
Even though was initially discovered in 2018, the available information regarding the vulnerability is still sparse.
In this paper, we analyze on 19 different CPUs from different vendors using an automated tool.
We observe that the impact is more diverse than documented and differs from CPU to CPU.
Surprisingly, while the newest Intel CPUs do not seem affected by , the newest available AMD CPUs (Zen3+
arXiv
Dynamic Process Isolation
arxiv_fulltext·2021-10-10
Dynamic Process Isolation
Dynamic Process Isolation
Martin Schwarzl
Graz University of Technology
[email protected]
Pietro Borrello
Sapienza University of Rome
[email protected]
Andreas Kogler
Graz University of Technology
[email protected]
Kenton Varda
Cloudflare
[email protected]
Thomas Schuster
Graz University of Technology
[email protected]
Daniel Gruss
Graz University of Technology
[email protected]
Michael Schwarz
CISPA Helmholtz Center for Information Security
[email protected]
empty
## Abstract
In the quest for efficiency and performance, edge-computing providers eliminate isolation boundaries between tenants, such as strict process isolation, and instead let them compute in a more lightweight multi-threaded single-
http://support.lenovo.com/us/en/solutions/LEN-22133http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.htmlhttp://www.securityfocus.com/bid/104228http://www.securitytracker.com/id/1040949http://www.securitytracker.com/id/1042004https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityhttps://lists.debian.org/debian-lts-announce/2018/07/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180013https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0005https://security.netapp.com/advisory/ntap-20180521-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03850en_ushttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180521-cpusidechannelhttps://usn.ubuntu.com/3756-1/https://www.debian.org/security/2018/dsa-4273https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.htmlhttps://www.kb.cert.org/vuls/id/180049https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0006https://www.synology.com/support/security/Synology_SA_18_23https://www.us-cert.gov/ncas/alerts/TA18-141Ahttp://support.lenovo.com/us/en/solutions/LEN-22133http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.htmlhttp://www.securityfocus.com/bid/104228http://www.securitytracker.com/id/1040949http://www.securitytracker.com/id/1042004https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityhttps://lists.debian.org/debian-lts-announce/2018/07/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180013https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0005https://security.netapp.com/advisory/ntap-20180521-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03850en_ushttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180521-cpusidechannelhttps://usn.ubuntu.com/3756-1/https://www.debian.org/security/2018/dsa-4273https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.htmlhttps://www.kb.cert.org/vuls/id/180049https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0006https://www.synology.com/support/security/Synology_SA_18_23https://www.us-cert.gov/ncas/alerts/TA18-141A
2018-05-22
Published