CVE-2018-3646
published 2018-08-14CVE-2018-3646: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data…
PriorityP335medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
8.10%
94.2th percentile
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.
Affected
482 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_mojave | — | — |
| apple | macos_mojave_10.14.1_security_update_2018-002_high_sierra_security_update_2018-0 | — | — |
| debian | intel-microcode | < intel-microcode 3.20180703.1 (bookworm) | intel-microcode 3.20180703.1 (bookworm) |
| debian | linux | < intel-microcode 3.20180703.1 (bookworm) | intel-microcode 3.20180703.1 (bookworm) |
| debian | xen | < intel-microcode 3.20180703.1 (bookworm) | intel-microcode 3.20180703.1 (bookworm) |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv3.05.6MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv5.6MEDIUM
vendor_cisco6.4MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware product updates enable Hypervisor-Specific Mitigations, Hypervisor-Assisted Guest Mitigations, and Operating System-Specific Mitigations for Microarchitectural Data Sampling (MDS) Vulnerabiliti
vendor_vmware·2019-05-14·CVSS 5.6
CVE-2018-12126 [MEDIUM] VMware product updates enable Hypervisor-Specific Mitigations, Hypervisor-Assisted Guest Mitigations, and Operating System-Specific Mitigations for Microarchitectural Data Sampling (MDS) Vulnerabiliti
VMSA-2019-0008: VMware product updates enable Hypervisor-Specific Mitigations, Hypervisor-Assisted Guest Mitigations, and Operating System-Specific Mitigations for Microarchitectural Data Sampling (MDS) Vulnerabilities (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091)
| Advisory Severity | Moderate | CVSSv3 Range | 3.8 - 6.5 | Synopsis | VMware product updates enable Hypervisor-Specific Mitigations, Hypervisor-Assisted Guest Mitigations, and Operating System-Specific Mitigations for Microarchitectural Data Sampling (MDS) Vulnerabilities (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091) | Issue Date | 2019-05-14 | Updated On | 2019-11-12 | CVE(s) | CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091 VMware vCenter Server (VC) VMware vSph
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-11-15·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were mitigated in the Linux kernel.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CV
Apple
CVE-2018-3646: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
vendor_apple·2018-10-30·CVSS 5.6
CVE-2018-3646 [MEDIUM] CVE-2018-3646: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
Product: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
CVE: CVE-2018-3646
Component: Hypervisor
Impact: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis
Description: An information disclosure issue was addressed by flushing the L1 data cache at the virtual machine entry.
Apple
CVE-2018-3646: macOS Mojave 10.14
vendor_apple·2018-09-24·CVSS 5.6
CVE-2018-3646 [MEDIUM] CVE-2018-3646: macOS Mojave 10.14
Apple Security Update: About the security content of macOS Mojave 10.14
Product: macOS Mojave
Version: 10.14
CVE: CVE-2018-3646
Component: Hypervisor
Impact: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis
Description: An information disclosure issue was addressed by flushing the L1 data cache at the virtual machine entry.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2018-08-27·CVSS 5.5
CVE-2018-3639 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: The system could be made to expose sensitive information.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
Jann Horn and Ken Johnson discovered that microprocessors utilizing
speculative execution of a memory read may allow unauthorized memory reads
via a sidechannel attack. This flaw is known as Spectre Variant 4. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2018-3639)
Zdenek So
Ubuntu
Linux kernel (Trusty HWE) regressions
vendor_ubuntu·2018-08-21·CVSS 5.5
CVE-2018-3620 [MEDIUM] Linux kernel (Trusty HWE) regressions
Title: Linux kernel (Trusty HWE) regressions
Summary: USN-3742-2 introduced regressions in the Linux Hardware Enablement
(HWE) kernel for Ubuntu 12.04 ESM.
USN-3742-2 introduced mitigations in the Linux Hardware Enablement
(HWE) kernel for Ubuntu 12.04 ESM to address L1 Terminal Fault (L1TF)
vulnerabilities (CVE-2018-3620, CVE-2018-3646). Unfortunately, the
update introduced regressions that caused kernel panics when booting
in some environments as well as preventing Java applications from
starting. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Ter
Palo Alto
PAN-SA-2018-0011 Information about L1 Terminal Fault findings
vendor_paloalto·2018-08-17·CVSS 6.4
CVE-2018-3615 [MEDIUM] CWE-200 PAN-SA-2018-0011 Information about L1 Terminal Fault findings
PAN-SA-2018-0011 Information about L1 Terminal Fault findings
Palo Alto Networks is aware of recent vulnerability disclosures, known as L1 Terminal Fault, that affect modern CPU architectures. At this time, our findings show that these vulnerabilities pose no increased risk to Palo Alto Networks PAN-OS devices. (CVE-2018-3615, CVE-2018-3620, and CVE-2018-3646). This security advisory will be updated as more information becomes available or if there are changes in the impact of these vulnerabilities. PAN-OS/Panorama platforms are not directly impacted by these vulnerabilities, as successful
CVEs: CVE-2018-3615, CVE-2018-3620, CVE-2018-3646
Affected products: PAN-OS, Panorama
Ubuntu
Linux kernel regressions
vendor_ubuntu·2018-08-17·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel regressions
Title: Linux kernel regressions
Summary: Several security issues were fixed in the Linux kernel.
USN-3741-1 introduced mitigations in the Linux kernel for Ubuntu 14.04
LTS to address L1 Terminal Fault (L1TF) vulnerabilities (CVE-2018-3620,
CVE-2018-3646). Unfortunately, the update introduced regressions
that caused kernel panics when booting in some environments as well
as preventing Java applications from starting. This update fixes
the problems.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to exp
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-20
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-20
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3741-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a mali
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.5
CVE-2017-18344 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3742-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 for Ubuntu
12.04 ESM.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a maliciou
BSD
FreeBSD-SA-18:09.l1tf: L1 Terminal Fault (L1TF) Kernel Information Disclosure
bsd_advisories·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] FreeBSD-SA-18:09.l1tf: L1 Terminal Fault (L1TF) Kernel Information Disclosure
FreeBSD-SA-18:09.l1tf Security Advisory
The FreeBSD Project
Topic: L1 Terminal Fault (L1TF) Kernel Information Disclosure
Category: core
Module: Kernel
Announced: 2018-08-14
Affects: All supported versions of FreeBSD.
Corrected: 2018-08-14 17:51:12 UTC (stable/11, 11.1-STABLE)
2018-08-15 02:30:11 UTC (releng/11.2, 11.2-RELEASE-p2)
2018-08-15 02:30:11 UTC (releng/11.1, 11.1-RELEASE-p13)
CVE Name: CVE-2018-3620, CVE-2018-3646
Special Note: Speculative execution vulnerability mitigation remains a work
in progress. This advisory addresses the issue in FreeBSD
11.1 and later. We expect to update this advisory to include
10.4 at a later time.
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following section
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.5
CVE-2017-18344 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-20
Red Hat
Kernel: hw: cpu: L1 terminal fault (L1TF)
vendor_redhat·2018-08-14·CVSS 5.6
CVE-2018-3646 [MEDIUM] CWE-226 Kernel: hw: cpu: L1 terminal fault (L1TF)
Kernel: hw: cpu: L1 terminal fault (L1TF)
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.
Modern operating systems implement virtualization of physical memory to efficiently use available system resources and provide inter-domain protection through access control and isolation. The L1TF issue was found in the way the x86 microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization) in combination with handling of page-faults caused by terminated virtual to physical address resolving process. As a res
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3740-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious p
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
vendor_cisco·2018-08-14·CVSS 6.4
CVE-2018-3615 [MEDIUM] CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
5On August 14th, 2018, three vulnerabilities were disclosed by Intel and security researchers that leverage a speculative execution side-channel method referred to as L1 Terminal Fault (L1TF) that affects modern Intel microprocessors. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes.
The first vulnerability, CVE-2018-3615, affects Intel SGX technology and is referred to by the researchers who discovered it as foreshadow. This vulnerability is not known to affect any Cisco devices as the Cisco devices do not utilize Intel SGX technology.
The second vulnerability, CVE-2018-3620, and the third vulnerability, CVE-2018-3646, ar
Debian
CVE-2018-3646: intel-microcode - Systems with microprocessors utilizing speculative execution and address transla...
vendor_debian·2018·CVSS 5.6
CVE-2018-3646 [MEDIUM] CVE-2018-3646: intel-microcode - Systems with microprocessors utilizing speculative execution and address transla...
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 3.20180703.1)
bullseye: resolved (fixed in 3.20180703.1)
forky: resolved (fixed in 3.20180703.1)
sid: resolved (fixed in 3.20180703.1)
trixie: resolved (fixed in 3.20180703.1)
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
vendor_cisco
CVE-2018-3646 CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
CVE-2018-3646: CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
5On August 14th, 2018, three vulnerabilities were disclosed by Intel and security researchers that leverage a speculative execution side-channel method referred to as L1 Terminal Fault (L1TF) that affects modern Intel microprocessors. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes. The first vulnerability, CVE-2018-3615, affects Intel SGX technology and is referred to by the researchers who discovered it as foreshadow. This vulnerability is not known to affect any Cisco devices as the Cisco devices do not utilize Intel SGX technology. The second vulnerability, CVE-2018-3620, and the third vulnerability, CVE
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
vendor_cisco
CVE-2018-3620 CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
CVE-2018-3620: CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
5On August 14th, 2018, three vulnerabilities were disclosed by Intel and security researchers that leverage a speculative execution side-channel method referred to as L1 Terminal Fault (L1TF) that affects modern Intel microprocessors. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes. The first vulnerability, CVE-2018-3615, affects Intel SGX technology and is referred to by the researchers who discovered it as foreshadow. This vulnerability is not known to affect any Cisco devices as the Cisco devices do not utilize Intel SGX technology. The second vulnerability, CVE-2018-3620, and the third vulnerability, CVE
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
vendor_cisco
CVE-2018-3615 CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
CVE-2018-3615: CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
5On August 14th, 2018, three vulnerabilities were disclosed by Intel and security researchers that leverage a speculative execution side-channel method referred to as L1 Terminal Fault (L1TF) that affects modern Intel microprocessors. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes. The first vulnerability, CVE-2018-3615, affects Intel SGX technology and is referred to by the researchers who discovered it as foreshadow. This vulnerability is not known to affect any Cisco devices as the Cisco devices do not utilize Intel SGX technology. The second vulnerability, CVE-2018-3620, and the third vulnerability, CVE
GHSA
GHSA-qj7r-58vw-6www: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the
ghsa_unreviewed·2022-05-13
CVE-2018-3646 [MEDIUM] GHSA-qj7r-58vw-6www: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.
OSV
intel-microcode vulnerabilities
osv·2018-08-27·CVSS 5.5
CVE-2018-3646 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
Jann Horn and Ken Johnson discovered that microprocessors utilizing
speculative execution of a memory read may allow unauthorized memory reads
via a sidechannel attack. This flaw is known as Spectre Variant 4. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2018-3639)
Zdenek Sojka, Rudolf Marek, Alex Zuepke, and Innokentiy Sennovskiy
discovered that m
OSV
linux regressions
osv·2018-08-17·CVSS 5.6
CVE-2018-3620 [MEDIUM] linux regressions
linux regressions
USN-3741-1 introduced mitigations in the Linux kernel for Ubuntu 14.04
LTS to address L1 Terminal Fault (L1TF) vulnerabilities (CVE-2018-3620,
CVE-2018-3646). Unfortunately, the update introduced regressions
that caused kernel panics when booting in some environments as well
as preventing Java applications from starting. This update fixes
the problems.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3
OSV
linux vulnerabilities
osv·2018-08-14·CVSS 5.5
CVE-2018-3646 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)
Andrey Konovalov discovered an out-of-bounds read in the POSIX
timers
Kernel
Merge branch 'l1tf-final' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
kernel_security·2018-08-14·CVSS 6.4
CVE-2018-3615 [MEDIUM] Merge branch 'l1tf-final' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Merge branch 'l1tf-final' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Merge L1 Terminal Fault fixes from Thomas Gleixner:
"L1TF, aka L1 Terminal Fault, is yet another speculative hardware
engineering trainwreck. It's a hardware vulnerability which allows
unprivileged speculative access to data which is available in the
Level 1 Data Cache when the page table entry controlling the virtual
address, which is used for the access, has the Present bit cleared or
other reserved bits set.
If an instruction accesses a virtual address for which the relevant
page table entry (PTE) has the Present bit cleared or other reserved
bits set, then speculative execution ignores the invalid PTE and loads
the referenced data if it is present in the Level 1 Data Cache, as if
the page referenced by
OSV
CVE-2018-3646: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the
osv·2018-08-14·CVSS 5.6
CVE-2018-3646 [MEDIUM] CVE-2018-3646: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-08-14·CVSS 5.6
CVE-2018-3646 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)
Juha-Matti Tilli
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2018-08-14·CVSS 5.6
CVE-2018-3646 [MEDIUM] linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)
OSV
linux-hwe, linux-azure, linux-gcp vulnerabilities
osv·2018-08-14·CVSS 5.6
[MEDIUM] linux-hwe, linux-azure, linux-gcp vulnerabilities
linux-hwe, linux-azure, linux-gcp vulnerabilities
USN-3740-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerabili
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-08-14·CVSS 5.6
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3741-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-3620 CVE-2018-3646 kernel: hw: cpu: L1 terminal fault (L1TF) [fedora-all]
bugzilla·2018-08-14·CVSS 5.6
CVE-2018-3620 [MEDIUM] CVE-2018-3620 CVE-2018-3646 kernel: hw: cpu: L1 terminal fault (L1TF) [fedora-all]
CVE-2018-3620 CVE-2018-3646 kernel: hw: cpu: L1 terminal fault (L1TF) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2018-3620 CVE-2018-3646 Kernel: hw: cpu: L1 terminal fault (L1TF)
bugzilla·2018-06-01·CVSS 5.6
CVE-2018-3620 [MEDIUM] CVE-2018-3620 CVE-2018-3646 Kernel: hw: cpu: L1 terminal fault (L1TF)
CVE-2018-3620 CVE-2018-3646 Kernel: hw: cpu: L1 terminal fault (L1TF)
Modern operating systems implement virtualization of physical memory to efficiently use available system resources and provide inter-domain protection through access control and isolation.
The L1TF issue was found in the way the x86 microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimisation) in combination with handling of page-faults caused by terminated virtual to physical address resolving process.
As a result, an unprivileged attacker could use this flaw to read privileged
memory of the kernel or other processes and/or cross guest/host boundaries to read host memory by conducting targeted cache side-channel attacks.
CVE-2018-3620: for attack vector agai
Tenable
Foreshadow: Speculative Execution Attack Targets Intel SGX
blogs_tenable·2018-08-14
Foreshadow: Speculative Execution Attack Targets Intel SGX
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Foreshadow: Speculative Execution Attack Targets Intel SGX
blogs_tenable·2018-08-14·CVSS 6.4
[MEDIUM] Foreshadow: Speculative Execution Attack Targets Intel SGX
Blog / Cyber Exposure Alerts
Subscribe
# Foreshadow: Speculative Execution Attack Targets Intel SGX
Ryan Seguin
August 14, 2018
2 Min Read
A flaw in Intel’s Software Guard Extensions implementation allows an attacker to access data stored in memory of other applications running on the same host, without the need for privilege escalation.
## Background
Researchers discovered a flaw in Intel’s Software Guard Extensions (SGX) implementation that opens up a new speculative execution attack called Foreshadow (CVE-2018-3615). In addition, Intel has discovered variants allowing for Foreshadow attacks against microprocessors, system management mode (SMM) code, operating systems and Hypervisor software. These variants have been dubbed Foreshadow-NG (CVE-2018-3620 and CVE-2018-3646).
Collect
Huntress
CVE-2018-3646 Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 5.6
CVE-2018-3646 [MEDIUM] CVE-2018-3646 Vulnerability: Analysis, Impact, Mitigation | Huntress
## CVE-2018-3646 Vulnerability
Published: 12/16/2025
Written by: Lizzie Danielson
## What is CVE-2018-3646 vulnerability?
CVE-2018-3646 is a critical security vulnerability classified as a speculative execution side-channel attack, specifically targeting Intel processors. It is part of the Spectre and Meltdown family, leveraging microarchitectural data sampling (MDS) to gain unauthorized access to sensitive data in affected systems. This vulnerability is exploitable in both hyperthreading-enabled environments and virtualized infrastructures, posing significant risks to multi-tenant cloud environments and systems handling confidential data.
## When was it discovered?
CVE-2018-3646 was disclosed publicly in August 2018 following extensive research on speculative execution vulnerabiliti
arXiv
The Ideal Versus the Real: Revisiting the History of Virtual Machines and Containers
arxiv_fulltext·2019-04-27
The Ideal Versus the Real: Revisiting the History of Virtual Machines and Containers
The Ideal Versus the Real: Revisiting the History of Virtual Machines and Containers
Allison Randal, University of Cambridge
## Abstract
The common perception in both academic literature and the industry
today is that virtual machines offer better security, while containers
offer better performance. However, a detailed review of the history of
these technologies and the current threats they face reveals a
different story. This survey covers key developments in the evolution
of virtual machines and containers from the 1950s to today, with an
emphasis on countering modern misperceptions with accurate historical
details and providing a solid foundation for ongoing research into the
future of secure isolation for multitenant infrastructures, such as
cloud and container deployments.
## Intr
http://support.lenovo.com/us/en/solutions/LEN-24163http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-enhttp://www.securityfocus.com/bid/105080http://www.securitytracker.com/id/1041451http://www.securitytracker.com/id/1042004http://www.vmware.com/security/advisories/VMSA-2018-0020.htmlhttp://xenbits.xen.org/xsa/advisory-273.htmlhttps://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2387https://access.redhat.com/errata/RHSA-2018:2388https://access.redhat.com/errata/RHSA-2018:2389https://access.redhat.com/errata/RHSA-2018:2390https://access.redhat.com/errata/RHSA-2018:2391https://access.redhat.com/errata/RHSA-2018:2392https://access.redhat.com/errata/RHSA-2018:2393https://access.redhat.com/errata/RHSA-2018:2394https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2018:2396https://access.redhat.com/errata/RHSA-2018:2402https://access.redhat.com/errata/RHSA-2018:2403https://access.redhat.com/errata/RHSA-2018:2404https://access.redhat.com/errata/RHSA-2018:2602https://access.redhat.com/errata/RHSA-2018:2603https://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://foreshadowattack.eu/https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/08/msg00029.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V4UWGORQWCENCIF2BHWUEF2ODBV75QS2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XRFKQWYV2H4BV75CUNGCGE5TNVQCLBGZ/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180018https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0010https://security.FreeBSD.org/advisories/FreeBSD-SA-18:09.l1tf.aschttps://security.gentoo.org/glsa/201810-06https://security.netapp.com/advisory/ntap-20180815-0001/https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-faulthttps://support.f5.com/csp/article/K31300402https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_ushttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannelhttps://usn.ubuntu.com/3740-1/https://usn.ubuntu.com/3740-2/https://usn.ubuntu.com/3741-1/https://usn.ubuntu.com/3741-2/https://usn.ubuntu.com/3742-1/https://usn.ubuntu.com/3742-2/https://usn.ubuntu.com/3756-1/https://usn.ubuntu.com/3823-1/https://www.debian.org/security/2018/dsa-4274https://www.debian.org/security/2018/dsa-4279https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.htmlhttps://www.kb.cert.org/vuls/id/982149https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.synology.com/support/security/Synology_SA_18_45http://support.lenovo.com/us/en/solutions/LEN-24163http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-enhttp://www.securityfocus.com/bid/105080http://www.securitytracker.com/id/1041451http://www.securitytracker.com/id/1042004http://www.vmware.com/security/advisories/VMSA-2018-0020.htmlhttp://xenbits.xen.org/xsa/advisory-273.htmlhttps://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2387https://access.redhat.com/errata/RHSA-2018:2388https://access.redhat.com/errata/RHSA-2018:2389https://access.redhat.com/errata/RHSA-2018:2390https://access.redhat.com/errata/RHSA-2018:2391https://access.redhat.com/errata/RHSA-2018:2392https://access.redhat.com/errata/RHSA-2018:2393https://access.redhat.com/errata/RHSA-2018:2394https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2018:2396https://access.redhat.com/errata/RHSA-2018:2402https://access.redhat.com/errata/RHSA-2018:2403https://access.redhat.com/errata/RHSA-2018:2404https://access.redhat.com/errata/RHSA-2018:2602https://access.redhat.com/errata/RHSA-2018:2603https://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://foreshadowattack.eu/https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/08/msg00029.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V4UWGORQWCENCIF2BHWUEF2ODBV75QS2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XRFKQWYV2H4BV75CUNGCGE5TNVQCLBGZ/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180018https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0010https://security.FreeBSD.org/advisories/FreeBSD-SA-18:09.l1tf.aschttps://security.gentoo.org/glsa/201810-06https://security.netapp.com/advisory/ntap-20180815-0001/https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-faulthttps://support.f5.com/csp/article/K31300402https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_ushttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannelhttps://usn.ubuntu.com/3740-1/https://usn.ubuntu.com/3740-2/https://usn.ubuntu.com/3741-1/https://usn.ubuntu.com/3741-2/
+ 12 more references
2018-08-14
Published